# What is the role of stdout { codec =\> rubydebug }

**URL:** <https://discuss.elastic.co/t/what-is-the-role-of-stdout-codec-rubydebug/232039>\
**Category:** Logstash\
**Created:** [May 11, 2020, 2:08pm UTC](https://discuss.elastic.co/t/what-is-the-role-of-stdout-codec-rubydebug/232039 "2020-05-11T14:08:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Devyani](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@Devyani](https://discuss.elastic.co/u/Devyani)\
**Post date:** [May 11, 2020, 2:08pm UTC](https://discuss.elastic.co/t/what-is-the-role-of-stdout-codec-rubydebug/232039/1 "2020-05-11T14:08:04Z")

</div>

I've created the following grok pattern to parse the log file--\>  
(?%{TIMESTAMP\_ISO8601}) %{LOGLEVEL:loglevel} \* (?[A-Za-z0-9$\_.]+) ((%{WORD:log-AppCode})?:(%{NOTSPACE:log-ServerId})?:(%{NOTSPACE:log-ProcessId})?:%{NOTSPACE:log-ThreadName}) %{GREEDYDATA:log-message} ((%{NOTSPACE:log-UserId})?:(%{NOTSPACE:log-TraceId})?:(%{NOTSPACE:log-SpanId})?:(%{NOTSPACE:log-ClientIP})?:(%{NOTSPACE:log-SessionId})?:(%{NOTSPACE:log-FlowId})?:(%{NOTSPACE:log-WidgetId})?) ([(%{DATA:log-AppVersion})?]:[(%{DATA:log-FwkVersion})?])%{SPACE}%{GREEDYDATA:exception-stacktrace}

It is working correctly to parse the multiline events as well when stdout { codec =\> rubydebug } is used in conf file.

But when I removed this line from output, multiline events doesn't parse.  
What can be the problem? Any help is most appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2020, 2:08pm UTC](https://discuss.elastic.co/t/what-is-the-role-of-stdout-codec-rubydebug/232039/2 "2020-06-08T14:08:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
