# Filebeat ignore all pattern

**URL:** <https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 16, 2022, 9:58am UTC](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705 "2022-10-16T09:58:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 16, 2022, 9:58am UTC](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705/1 "2022-10-16T09:58:41Z")

</div>

i used simple config

```auto
parsers:
- multiline:
    type: pattern
    pattern: '^test'
    negate: false
    match: after

output.console:
     pretty: true

```

```auto
ter_id":"41e9015a-67cd-4e5a-b602-6ce8a0eba50d","ecs.version":"1.6.0"}
{
  "@timestamp": "2022-10-16T10:00:03.092Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "_doc",
    "version": "8.4.3"
  },
  "input": {
    "type": "log"
  },
  "ecs": {
    "version": "8.0.0"
  },
  "host": {
    "name": "nturri-HP"
  },
  "agent": {
    "ephemeral_id": "85c44e17-dfb7-472f-b57a-be5d14f43dab",
    "id": "0b4a67a1-c70a-4110-9dea-26571614c0dd",
    "name": "nturri-HP",
    "type": "filebeat",
    "version": "8.4.3"
  },
  "log": {
    "file": {
      "path": "G:\\filebeat-8.4.3-windows-x86_64\\logs\\test2.log"
    },
    "offset": 0
  },
  "message": "hello how are you"
}
{
  "@timestamp": "2022-10-16T10:00:03.092Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "_doc",
    "version": "8.4.3"
  },
  "log": {
    "offset": 19,
    "file": {
      "path": "G:\\filebeat-8.4.3-windows-x86_64\\logs\\test2.log"
    }
  },
  "message": "test",
  "input": {
    "type": "log"
  },
  "agent": {
    "id": "0b4a67a1-c70a-4110-9dea-26571614c0dd",
    "name": "nturri-HP",
    "type": "filebeat",
    "version": "8.4.3",
    "ephemeral_id": "85c44e17-dfb7-472f-b57a-be5d14f43dab"
  },
  "ecs": {
    "version": "8.0.0"
  },
  "host": {
    "name": "nturri-HP"
  }
}
{
  "@timestamp": "2022-10-16T10:00:03.092Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "_doc",
    "version": "8.4.3"
  },
  "input": {
    "type": "log"
  },
  "agent": {
    "type": "filebeat",
    "version": "8.4.3",
    "ephemeral_id": "85c44e17-dfb7-472f-b57a-be5d14f43dab",
    "id": "0b4a67a1-c70a-4110-9dea-26571614c0dd",
    "name": "nturri-HP"
  },
  "ecs": {
    "version": "8.0.0"
  },
  "host": {
    "name": "nturri-HP"
  },
  "log": {
    "offset": 25,
    "file": {
      "path": "G:\\filebeat-8.4.3-windows-x86_64\\logs\\test2.log"
    }
  },
  "message": "i am fine "
}

```

```auto
hello how are you
test
i am fine 
and you

```

but never apply this

i see this video and version 6 is functionally

```auto

[Filebeat Demo- Multiline configuration | how to read multiple lines at a time from log file . - YouTube](https://www.youtube.com/watch?v=823ZdeebCDI)

```

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 16, 2022, 12:35pm UTC](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705/2 "2022-10-16T12:35:44Z")

</div>

hello i've resolved with

filebeat.inputs:

- type: filestream  
paths:  
- G:\filebeat-8.4.3-windows-x86\_64\logs\*.\*

output.logstash:  
hosts: ["172.22.13.178:5044"]  
protocol: "http"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 17, 2022, 2:04am UTC](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705/3 "2022-10-17T02:04:42Z")

</div>

Thanks for sharing your solution.

In future please also be mindful of where you are putting your topics, they don't all belong in #elastic-stack:elasticsearch 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2022, 2:04am UTC](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705/4 "2022-11-14T02:04:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
