# Filbeat exclude and multiline configuration

**URL:** <https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 14, 2020, 11:26pm UTC](https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042 "2020-06-14T23:26:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nmoham](https://avatars.discourse-cdn.com/v4/letter/n/77aa72/32.png) [@nmoham](https://discuss.elastic.co/u/nmoham)\
**Post date:** [June 14, 2020, 11:26pm UTC](https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042/1 "2020-06-14T23:26:05Z")

</div>

Example Events -

```auto
time,thread,logger,level,message
2020-06-11 09:46:50.3836,7,Logs.Shared.ServiceBehaviors.ServiceExceptionHandlerBehavior,Debug,applying ServiceExceptionHandler to UsersService
time,thread,logger,level,message
2020-06-11 10:48:58.2763,7,Logs.Shared.ServiceBehaviors.ServiceExceptionHandlerBehavior,Debug,applying ServiceExceptionHandler to UsersService
time,thread,logger,level,message
2020-06-11 12:09:19.0674,10,Logs.Shared.ServiceBehaviors.ServiceExceptionHandlerBehavior,Debug,applying ServiceExceptionHandler to UsersService
time,thread,logger,level,message
2020-06-11 13:04:28.3982,10,Logs.Shared.ServiceBehaviors.ServiceExceptionHandlerBehavior,Debug,applying ServiceExceptionHandler to UsersService

```

I am trying to exclude the line `time,thread,logger,level,message` and at the sametime, I may have multiple lines to the original event.

I'm using the following processor, so that all the log files as inputs are affected -

```auto
  - drop_event:
      when:
        regexp:
          message: "^time|.*Signal.*|.*MetricsErrorHandler.*"

```

I also tried exclude lines, but the events `time,thread,logger,level,message` are getting appended to the log event of interest.

```auto
  multiline.pattern: '^[0-9]{4}-[0-9]{2}-[0-9]{2}'
  multiline.negate: true
  multiline.match: after

```

Appreciate any ideas / help.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [June 15, 2020, 8:45am UTC](https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042/2 "2020-06-15T08:45:08Z")

</div>

I'm not sure about the internals of Filebeat in this case, but I'll try making a less strict pattern. Maybe remove the `^` in `^time|` and simply write `time,thread,logger,level,message` directly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2020, 10:45am UTC](https://discuss.elastic.co/t/filbeat-exclude-and-multiline-configuration/237042/3 "2020-07-13T10:45:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
