# Config file for multiple multi-line patterns?

**URL:** <https://discuss.elastic.co/t/config-file-for-multiple-multi-line-patterns/273877>\
**Category:** Logstash\
**Created:** [May 25, 2021, 12:31am UTC](https://discuss.elastic.co/t/config-file-for-multiple-multi-line-patterns/273877 "2021-05-25T00:31:33Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![1steve](https://avatars.discourse-cdn.com/v4/letter/1/f05b48/32.png) [@1steve](https://discuss.elastic.co/u/1steve)\
**Post date:** [May 25, 2021, 2:53pm UTC](https://discuss.elastic.co/t/config-file-for-multiple-multi-line-patterns/273877/3 "2021-05-25T14:53:18Z")

</div>

> [@Badger](#):
>
> What tells you that the tail end of the file has started?

This line;

```auto
------------------------------------------------------------

```

shows that the tail end of the log has started, and everything after that should be considered one entry.

On its own I do not think it would be that difficult to set the Logstash input multiline codec to detect this, the problem is that I _already_ have that codec configured to detect tracebacks (indented lines) and bundle those as well. So I am not sure how to tell the multiline code to detect two different patterns. I looked into Filebeat's multiline handling, and could not figure out how to specify [multiple multiline patterns](https://discuss.elastic.co/t/multiple-multiline-patterns/127848) on there either.

For context, this is because my log is actually the output of two different programs, the [Toil](https://toil.readthedocs.io/en/latest/) CWL workflow runner, running inside of an [LSF](https://www.ibm.com/products/hpc-workload-management) HPC job.

---

_[View the full topic](https://discuss.elastic.co/t/config-file-for-multiple-multi-line-patterns/273877)._
