I have attacted the conf, sincedb, and log file. The event parsing is not working. If the input log file has only one event, it does not get detected. If the input log has mulitple events, the event next to the last is being parsed twice (even though is was already parsed previosuly) in addition to the last event.

Please explain how is the parsing suppose to work and what can I do to prevent these unwanted actions.


MAYDAY- Please help out anyone. How come start_position does not work as expected? Please someone have mercy and help out here?

Please help me out, sir. I need to get some answers by today COB. Thanks.

There appears to be an issue with start_position and any help would be most helpful.

I had a quick look at your issue and your configs.
The first issue i find is that you specify your multiline pattern as "%{LOGLEVEL} +%{TIMESTAMP_ISO8601}" while the first line contains much more then that.
Could you try it out with "%{LOGLEVEL} +%{TIMESTAMP_ISO8601} %{GREEDYDATA}" ?
The greedydata pattern should match anything behind the timestamp.


Can OP please comment?


