Logstash Multiline过滤器配置求助:按<<ERROR>>分段捕获日志
Let's get this sorted out! The issue with your current configuration is that your pattern is overly broad and the logic isn't targeting the actual delimiter of your log entries—those <<ERROR>> markers. Instead of trying to match every possible line in the stack trace, we need to focus on identifying when a new log entry starts, which is exactly when a line begins with <<ERROR>>.
Here's the corrected multiline filter configuration that will group each block from one <<ERROR>> to the next as a single event:
filter { multiline { pattern => "^<<ERROR>>" negate => true what => "previous" } }
How this works:
pattern => "^<<ERROR>>": We're matching any line that starts with your log entry delimiter<<ERROR>>.negate => true: This reverses the match—so we're targeting lines that do NOT start with<<ERROR>>.what => "previous": All non-matching lines (the stack trace lines, follow-up messages) get appended to the previous event (the one that started with<<ERROR>>).
When a new line starting with <<ERROR>> comes in, Logstash will start a fresh event, and all subsequent non-delimiter lines will attach to that new event until the next <<ERROR>> is encountered. This perfectly aligns with your requirement of capturing each <<ERROR>> block as a single message.
Why your original config failed:
Your initial pattern tried to match multiple line types (exception messages, stack trace lines, etc.) and used negate: true, which meant it was treating lines that didn't match those patterns as needing to be merged. This broad logic ended up merging everything into one giant event instead of splitting at the <<ERROR>> markers.
Quick test tip:
You can verify this works by using Logstash's stdin input for testing. Run Logstash with this config, paste your sample log content into the terminal, and check the output—you should see two distinct events, each containing one full <<ERROR>> block.
内容的提问来源于stack exchange,提问作者Vineet Sharma

