Multiline filter with Windows Event Log


I am trying use the multiline plugin with windows event logs
stdout of a event log looks like this:

This is my logstash conf

In my logstash conf what im trying to achieve is : The line which is not starting with a number belongs to the previous line. But this doesn't give me any out put. Have i done any mistakes in the configuration file? Please advice.


Philippe Weber
May 16, 2014, 9:59 AM

Using multiline filter or codec with what => previous configuration causes the event to not be sent before the next event arrives.
This is a known issue already registered in and


Logstash Developers


Chamara Keragala