# Filebeat multiline concatenates all events that does not match the pattern

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 19, 2021, 9:41am UTC](https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779 "2021-03-19T09:41:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![seso](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@seso](https://discuss.elastic.co/u/seso)\
**Post date:** [March 19, 2021, 9:41am UTC](https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779/1 "2021-03-19T09:41:46Z")

</div>

I have the following multiline pattern to handle Java stack traces:  
`multiline.type: pattern`  
`multiline.pattern: '^\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2}.\d{3}'`  
`multiline.negate: true`  
`multiline.match: after`  
It works fine for java logs.  
However, all non-java logs that are collected from other applications are concatenated in a multiline message split every 5 sec when timeout occurs. Start of the line in those logs is totally different and it does not match the pattern.  
Why is everything is multilined, if no pattern is found? Is this intended behaviour?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [March 22, 2021, 9:28am UTC](https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779/2 "2021-03-22T09:28:49Z")

</div>

Hi!

I'm not sure what this pattern does however there are some Java specific examples you can check at [Manage multiline messages | Filebeat Reference [7.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#_java_stack_traces).

Also in the same docs page there is a playground link where you can check your patterns against the sample input so as to verify if the pattern matches the log or not.

If you make sure that logs do not match the pattern but they are grouped in the multiline then please open a Github issue to report this since I see that it shouldn't happen like this.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 11:29am UTC](https://discuss.elastic.co/t/filebeat-multiline-concatenates-all-events-that-does-not-match-the-pattern/267779/3 "2021-04-19T11:29:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
