I am trying to index multiline input into graylog
and following below steps,
In my collector , configure beats input I enabled Enable Multiline option and in Start pattern of a multiline message I mentioned my inputs start with Mon so I give [’^Mon’]
In this case its taking only first line and ignoring remaining lines .
Multiline pattern is negated:
If I enable Multiline pattern is negated ,its taking all lines in to single message .
please help me to resolve the multiline index.
Mon Dec 11 09:26:37 2017 777777 : : The selected Change Requester is not valid. Use the Return function on the Last Name, First Name, or Phone Number fields to retrieve the Requester’s information. (ERROR 77777)
Mon Dec 11 09:26:37 2017 888888 : : The Assignment Information is not valid.
Please use the menus provided on the ’ Company’, ’ Organization’ and ’ Group’ or the type ahead return function on the ’ Group’ field to select this information. (ERROR 88888)