# File beat Multiline issue

**URL:** https://discuss.elastic.co/t/file-beat-multiline-issue/347567
**Category:** Beats
**Tags:** filebeat
**Created:** [November 21, 2023, 2:36am UTC](https://discuss.elastic.co/t/file-beat-multiline-issue/347567 "2023-11-21T02:36:51Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![apsh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apsh/32/126751_2.png) [@apsh](https://discuss.elastic.co/u/apsh)
#### Post date: [November 21, 2023, 2:36am UTC](https://discuss.elastic.co/t/file-beat-multiline-issue/347567/1 "2023-11-21T02:36:51Z")

</div>

Hello! I am trying to use filebeat's multiline support to combine Node.js exceptions into a single message. However, all errors start with a date and there is no unique identifier to create a pattern for this error log. I was wondering if there are any tips I can use to create a pattern that only consolidates error messages to one message. Anything I have tried so far has combined almost any other log message with the same timestamp into one message.

This is sample error log :

```auto
count the logs that I mentioned earlier and end the pattern exactly after last line Nov 20 23:45:22 ip-172-31-1-132 web[235438]: throw new Error('💥 Test Exception! 💥');
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: ^
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: Error: 💥 Test Exception! 💥
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at getErrorCheck (/var/app/current/js/errorcheck.js:2:9)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at Layer.handle [as handle_request] (/var/app/current/node_modules/express/lib/router/layer.js:95:5)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at next (/var/app/current/node_modules/express/lib/router/route.js:137:13)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at Route.dispatch (/var/app/current/node_modules/express/lib/router/route.js:112:3)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at Layer.handle [as handle_request] (/var/app/current/node_modules/express/lib/router/layer.js:95:5)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at /var/app/current/node_modules/express/lib/router/index.js:281:22
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at Function.process_params (/var/app/current/node_modules/express/lib/router/index.js:335:12)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at next (/var/app/current/node_modules/express/lib/router/index.js:275:10)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at /var/app/current/js/index.js:84:5
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: at Layer.handle [as handle_request] (/var/app/current/node_modules/express/lib/router/layer.js:95:5)
Nov 20 23:45:22 ip-172-31-1-132 web[235438]: Node.js v18.18.0
Nov 20 23:45:22 ip-172-31-1-132 web[235813]: > XXX@3.8.35 start
Nov 20 23:45:22 ip-172-31-1-132 web[235813]: > node -r esm -r dotenv/config js/index.js

```

the last thing I tried was defining a unique pattern as follows but my pattern that doesn't combine any messages at all :

```auto
filebeat.inputs:
- type: filestream
  id: my-filestream-id
  enabled: true
  paths:
    - /var/log/web.stdout.log
  enabled: true
  parsers:
    - multiline:
        type: pattern
        pattern: '^\d{2}-\w{3}-\d{4}.*throw new Error:'
        negate: false
        match: after
        multiline.flush_pattern: '^> node'

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 19, 2023, 9:08am UTC](https://discuss.elastic.co/t/file-beat-multiline-issue/347567/4 "2023-12-19T09:08:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
