# Graylog not parsing hostname in log messages

**URL:** <https://community.graylog.org/t/graylog-not-parsing-hostname-in-log-messages/23678>\
**Category:** Graylog Central (peer support)\
**Created:** [May 3, 2022, 5:28am UTC](https://community.graylog.org/t/graylog-not-parsing-hostname-in-log-messages/23678 "2022-05-03T05:28:58Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 3, 2022, 10:46pm UTC](https://community.graylog.org/t/graylog-not-parsing-hostname-in-log-messages/23678/3 "2022-05-03T22:46:58Z")

</div>

Hello,

> [@tuaris](#):
>
> The message does indeed apear to be multi-line as suspected in the referenced post:

I did find this post [here](https://community.graylog.org/t/parse-multiline-messages/16924) but unfortunately I don’t see it resolved.

The screenshots look like firewall/switch messages? So you probably cant use a log shipper. If you could, FileBeat would be able to correct this issue with multi-line messages.

If this is correct and these messages/logs are from Firewall/Switch then a pipeline would be your best bet for correcting this.

Here are some links I found they might help.

> [@Graylog pipeline regex multi match](https://community.graylog.org/t/graylog-pipeline-regex-multi-match/16131):
>
> Hello, From what I understand from several places (e.g. there: [Can a pipeline rule to match the same pattern multiple times?](https://community.graylog.org/t/can-a-pipeline-rule-to-match-the-same-pattern-multiple-times/10511)), if a group in my regex happens several times in the original string, I should be able to get several matches. However, I’m not, so there’s something I must misunderstand. For example, here’s a very basic example of a rule, input, and what I get in the pipeline simulator: rule: when has\_field("test") then let result = regex("([0-9])", to\_string($message.message));…

[https://graylog.zammad.com/help/en-us/15-pipeline-rule-samples](https://graylog.zammad.com/help/en-us/15-pipeline-rule-samples)

FileBeat

- [Manage multiline messages | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)

---

_[View the full topic](https://community.graylog.org/t/graylog-not-parsing-hostname-in-log-messages/23678)._
