# Parse Multiline Messages

**URL:** <https://community.graylog.org/t/parse-multiline-messages/16924>\
**Category:** Graylog Central (peer support)\
**Created:** [August 25, 2020, 7:54pm UTC](https://community.graylog.org/t/parse-multiline-messages/16924 "2020-08-25T19:54:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tfpk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tfpk/32/7240_2.png) [@tfpk](https://community.graylog.org/u/tfpk)\
**Post date:** [August 25, 2020, 7:54pm UTC](https://community.graylog.org/t/parse-multiline-messages/16924/1 "2020-08-25T19:54:46Z")

</div>

I’m trying to parse the message below which comes into the full\_message field on the GELF TCP input.

I’m having issues with creating an extractor on a multiline field, I have tried grok patterns with (?s) as suggested [here](https://github.com/Graylog2/graylog2-server/issues/2465) but it didn’t seem to do anything. I also tried regex but its the same issue of only being able to use 1 line.

I also tried to use a pipeline but I’m having trouble figuring out the coding any help would be greatly appreciated. An example of how i might do it would be great too.

> A directory service object was modified.
> 
> Subject:  
> Security ID: S-1-5-21-2204958825-1778247899-2594878194-3373  
> Account Name: user12  
> Account Domain: domain  
> Logon ID: 0x11D9404F4
> 
> Directory Service:  
> Name: `domain.com`  
> Type: Active Directory Domain Services
> 
> Object:  
> DN: CN=user name,OU=ExcludeFromPhoneDirectory,OU=IT,OU=domainUsers,OU=domainDomainResources,DC=domain,DC=local  
> GUID: {25DF5F5C-5E69-45A0-BDCF-41BDDF42B88B}  
> Class: user
> 
> Attribute:  
> LDAP Display Name: userPrincipalName  
> Syntax (OID): 2.5.5.12  
> Value: `user1@domain.com`
> 
> Operation:  
> Type: Value Added  
> Correlation ID: {43F7C446-9D4F-4FF9-A433-34DEC6ACBBB9}  
> Application Correlation ID: -

I’m looking for an output for each value ie.

> **Security ID**  
> S-1-5-21-2204958825-1778247899-2594878194-3373
> 
> **Account Name**  
> user12
> 
> **Account Domain**  
> domain
> 
> **Logon ID**  
> 0x11D9404F4

---

<div class="post-metadata">

**Author:** ![tfpk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tfpk/32/7240_2.png) [@tfpk](https://community.graylog.org/u/tfpk)\
**Post date:** [August 26, 2020, 3:42pm UTC](https://community.graylog.org/t/parse-multiline-messages/16924/2 "2020-08-26T15:42:26Z")

</div>

I did try using a pipeline with the code below but it doesn’t seem to do anything and I’m not sure why.

```
rule "Parse full_message EventID 5136"
when
    true
then
    let msg = parse_json(to_string($message.full_message));
    let prop = select_jsonpath(msg, {Type: "$.Operation.Type"});
    set_field("Type", to_string(prop.Type));
    let props = parse_json(to_string($message.Type));
    set_fields(to_map(props));
end
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 9, 2020, 3:42pm UTC](https://community.graylog.org/t/parse-multiline-messages/16924/3 "2020-09-09T15:42:29Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
