# Filebeat multi line pattern not working

**URL:** <https://discuss.elastic.co/t/filebeat-multi-line-pattern-not-working/378301>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 19, 2025, 1:56pm UTC](https://discuss.elastic.co/t/filebeat-multi-line-pattern-not-working/378301 "2025-05-19T13:56:07Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 19, 2025, 5:05pm UTC](https://discuss.elastic.co/t/filebeat-multi-line-pattern-not-working/378301/6 "2025-05-19T17:05:54Z")

</div>

> [@manikandanid](#):
>
> ```auto
> multiline.pattern: '^\d{4}/\d{2}/\d{2} \d{2}:\d{2}:\d{2} (AM|PM)' 
> multiline.negate: true
> multiline.match: after
> scan.start_position: beginning
> ignore_older: 0s
> 
> ```

You are using the wrong syntax for filestream that is old `log` type syntax

> **[Manage multiline messages | Elastic Documentation](https://www.elastic.co/docs/reference/beats/filebeat/multiline-examples#multiline)**
>
> The files harvested by Filebeat may contain messages that span multiple lines of text. For example, multiline messages are common in files that contain...

```auto
- type: filestream

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /Users/sbrown/workspace/sample-data/discuss/filebeat-multiline/test-log-378301.log
    #- c:\programdata\elasticsearch\logs\*
  parsers:
    - multiline:
        type: pattern
        pattern: '^\d{4}/\d{2}/\d{2} \d{2}:\d{2}:\d{2} (AM|PM)' 
        negate: true
        match: after

```

That worked for me results

```auto
{
	"@timestamp": "2025-05-19T17:03:54.690Z",
	"@metadata": {
		"beat": "filebeat",
		"type": "_doc",
		"version": "8.17.2"
	},
	"container": {
		"id": "discuss"
	},
	"message": "2025/04/29 06:17:07 AM\nSystem.Exception: ServiceCode not found wrongservicecode.\n",
	"log": {
		"flags": [
			"multiline"
		],
		"offset": 267,
		"file": {
			"path": "/Users/sbrown/workspace/sample-data/discuss/filebeat-multiline/test-log-378301.log",
			"device_id": "16777221",
			"inode": "144197757"
		}
	},
	"input": {
		"type": "filestream"
	},

```

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-multi-line-pattern-not-working/378301)._
