# Websphere multiline logs

**URL:** <https://discuss.elastic.co/t/websphere-multiline-logs/132923>\
**Category:** Logstash\
**Created:** [May 23, 2018, 4:07am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923 "2018-05-23T04:07:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saketh\_Chandra\_Kolis](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Post date:** [May 23, 2018, 4:07am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/1 "2018-05-23T04:07:24Z")

</div>

This is what my log file looks like:  
[3/12/18 5:28:05:364 EDT] 00000056 AutowiredAnno I org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor JSR-330 'javax.inject.Inject' annotation found and supported for autowiring

i have used the following multiline codec:

multiline{  
pattern =\> "^DATESTAMP"  
negate =\> true  
what =\> previous  
}

and used the following grok pattern:  
grok{  
match =\> { "message" =\> "%{DATESTAMP:TIMESTAMP} EDT] %{WORD:ID} %{WORD:CLASS} %{WORD:event\_type} %{GREEDYDATA:MSG}" }  
}  
Logstash pipeline starts but i dont see any logs being parsed.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 23, 2018, 4:19am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/2 "2018-05-23T04:19:44Z")

</div>

> pattern =\> "^DATESTAMP"

Two problems:

- Your log line actually begins with `[` so you need to include that (escaped with a backslash).
- You need to reference the pattern as `%{DATESTAMP}`.

---

<div class="post-metadata">

**Author:** ![Saketh\_Chandra\_Kolis](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Post date:** [May 23, 2018, 4:36am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/3 "2018-05-23T04:36:35Z")

</div>

hi magnus,  
i made the changes as you said but the logs are not getting parsed.(the pipeline starts but nothing happens after that)  
here is my full configuration:

input{  
file{  
path=\>"C:/Users/Mahe/Desktop/internship/sample1.log"  
start\_position=\>"beginning"  
sincedb\_path =\> "/dev/null"  
codec=\>multiline{  
pattern =\> "^[%{DATESTAMP}"  
negate =\> true  
what =\> previous  
}  
}  
}

filter{

```
grok{
		match => { "message" => "%{DATESTAMP:TIMESTAMP} EDT] %{WORD:ID} %{WORD:CLASS} %{WORD:event_type} %{GREEDYDATA:MSG}" }
}

```

}

output{  
elasticsearch {  
hosts =\>"localhost"  
index=\>"my1.0"  
document\_type=\>"my\_logs"

```
 }
stdout {}

```

}

---

<div class="post-metadata">

**Author:** ![Saketh\_Chandra\_Kolis](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Post date:** [May 23, 2018, 4:37am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/4 "2018-05-23T04:37:34Z")

</div>

is there any problem in the grok filter

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 23, 2018, 6:01am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/5 "2018-05-23T06:01:27Z")

</div>

> sincedb\_path =\> "/dev/null"

On Windows use "nul" instead of "/dev/null".

---

<div class="post-metadata">

**Author:** ![Saketh\_Chandra\_Kolis](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Post date:** [May 23, 2018, 6:39am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/6 "2018-05-23T06:39:49Z")

</div>

hi magnus,  
no change

Sending Logstash's logs to C:/logstash-5.4.1/logs which is now configured via log4j2.properties  
[2018-05-23T12:05:36,500][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-05-23T12:05:36,508][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-05-23T12:05:36,717][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>#\<URI::HTTP:0x36a1f3ad URL:[http://localhost:9200/](http://localhost:9200/)\>}  
[2018-05-23T12:05:36,724][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-05-23T12:05:36,853][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword"}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-05-23T12:05:36,879][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>[#\<URI::Generic:0x7d51463d URL://localhost\>]}  
[2018-05-23T12:05:36,961][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500}  
[2018-05-23T12:05:37,552][INFO][logstash.pipeline] Pipeline main started  
[2018-05-23T12:05:37,742][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

pipe line gets started but the logs are not parsed

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 23, 2018, 6:49am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/7 "2018-05-23T06:49:35Z")

</div>

What happens if you disable the multiline codec?

---

<div class="post-metadata">

**Author:** ![Saketh\_Chandra\_Kolis](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Post date:** [May 23, 2018, 6:52am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/8 "2018-05-23T06:52:38Z")

</div>

no change even if the multiline codec is disabled,pattern seems to work fine where i used it on the grok debugger

---

<div class="post-metadata">

**Author:** ![Saketh\_Chandra\_Kolis](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Post date:** [May 23, 2018, 7:03am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/9 "2018-05-23T07:03:43Z")

</div>

[3/12/18 5:28:05:364 EDT] 00000056 AutowiredAnno I org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor JSR-330 'javax.inject.Inject' annotation found and supported for autowiring

%{DATESTAMP:TIMESTAMP} EDT] %{WORD:ID} %{WORD:CLASS} %{WORD:event\_type} %{GREEDYDATA:msg}

this is the output i get on grok debugger:  
{  
"TIMESTAMP": [  
[  
"3/12/18 5:28:05:364"  
]  
],  
"ID": [  
[  
"00000056"  
]  
],  
"CLASS": [  
[  
"AutowiredAnno"  
]  
],  
"event\_type": [  
[  
"I"  
]  
],  
"msg": [  
[  
"org.springframework.beans.factory.annotation.AutowiredAnnotationBeanPostProcessor JSR-330 'javax.inject.Inject' annotation found and supported for autowiring"  
]  
]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2018, 7:03am UTC](https://discuss.elastic.co/t/websphere-multiline-logs/132923/10 "2018-06-20T07:03:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
