# Shipping multiline logs to Graylog

**URL:** <https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531>\
**Category:** Graylog Central (peer support)\
**Created:** [August 31, 2022, 1:58pm UTC](https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531 "2022-08-31T13:58:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![H2Cyber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/h2cyber/32/12536_2.png) [@H2Cyber](https://community.graylog.org/u/H2Cyber)\
**Post date:** [August 31, 2022, 1:58pm UTC](https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531/1 "2022-08-31T13:58:10Z")

</div>

I have an application that produces logs in the following format :

```auto
[#|2022-08-31T13:23:51.641+0100|INFO|glassfish3.1.2|redacted|_ThreadID=44;_ThreadName=Thread-2;|DEBUG SomeRandomText
SomeOthorRandomTextinAnotherLine
|#]

[#|2022-08-31T13:23:51.650+0100|INFO|glassfish3.1.2|redacted|_ThreadID=33;_ThreadName=Thread-2;|INFO RandomText
|#]

[#|2022-08-31T13:23:51.654+0100|INFO|glassfish3.1.2|redacted|_ThreadID=50;_ThreadName=Thread-2;|INFO AnotherRandomText
AnotherRandomTextinASeperateLine
AnotherRandomTextinAnotherSeperateLine
AnotherRandomTextinAThirdSeperateLine
|#]

```

As you can see in the three messages above, a single log message starts with `[#|` and ends with `|#]`. The single log can spawn multiple lines, and the number of lines varies from one log to another.

Did anyone experience with shipping similar multi-line logs to Graylog ? What method would you recommend in this case to send the logs to Graylog ?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [August 31, 2022, 2:55pm UTC](https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531/2 "2022-08-31T14:55:42Z")

</div>

How is the message being shipped? If it’s filebeat, you can likely use the [multi-line message feature](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html) to define beginning and end of each message - I am sure NXlog has something similar but I don’t use that. If you don’t have control on shipping, what input are you using? You could likely break that up with a pipeline rule.

---

<div class="post-metadata">

**Author:** ![H2Cyber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/h2cyber/32/12536_2.png) [@H2Cyber](https://community.graylog.org/u/H2Cyber)\
**Post date:** [August 31, 2022, 4:56pm UTC](https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531/3 "2022-08-31T16:56:21Z")

</div>

The messages are not being shipped just yet, as I am still figuring that part out.

Given the constraints that I have (which I cannot disclose) Syslog is preferable, but if it has to be Filebeat then I’ll use that. I am open to suggestions or recommendations should you have other ideas 🙂

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [August 31, 2022, 10:10pm UTC](https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531/4 "2022-08-31T22:10:35Z")

</div>

Hello,  
You can use Nxlog, most preferred FileBeat. Personally I use both.

> **[Parsing multi-line logs :: NXLog Documentation](https://docs.nxlog.co/userguide/configure/multiline.html)**
>
> This topic explains the multi-line log parsing capabilities of NXLog.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 14, 2022, 10:10pm UTC](https://community.graylog.org/t/shipping-multiline-logs-to-graylog/25531/5 "2022-09-14T22:10:58Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
