I have a problem with '\n' from multiline filter.
Using multiline I try to create a grok pattern for the following log:
This Is my filter conf:
This Is my grok: 'ossec.grok'
I can't match the complete event. I can match different part of the event but can t pass any '\n'.I try different regexp to match '\n' but I t s not working.
Please let me know,
Right now, the grok filter defaults to not matching new lines.
However, you can likely achieve this by putting (?m) at the beginning of your grok pattern (which should enable it to match across line breaks)
(?m) at the beginning of my grok pattern solved my problem.