# Filebeat multiline how to parse both structured and unstructured logs in a file?

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-how-to-parse-both-structured-and-unstructured-logs-in-a-file/363335>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 18, 2024, 9:03am UTC](https://discuss.elastic.co/t/filebeat-multiline-how-to-parse-both-structured-and-unstructured-logs-in-a-file/363335 "2024-07-18T09:03:45Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tom\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tom_n/32/136135_2.png) [@Tom\_N](https://discuss.elastic.co/u/Tom_N)\
**Post date:** [July 18, 2024, 9:03am UTC](https://discuss.elastic.co/t/filebeat-multiline-how-to-parse-both-structured-and-unstructured-logs-in-a-file/363335/1 "2024-07-18T09:03:45Z")

</div>

I am currently trying to use multiline to parse my files. They are inputted into filebeat using filestream.

The logs in the file follow a structured format, except for the first log and last log

```auto
[2015-08-24 11:49:14,385] first log
[2015-08-24 11:49:14,389] Start new event #start of log 1
[2015-08-24 11:49:14,395] event 1
[2015-08-24 11:49:14,399] End event #end of log 1
[2015-08-24 11:49:14,403] Start new event
[2015-08-24 11:49:14,407] event 2
[2015-08-24 11:49:14,411] End event
.
.
.
[2015-08-24 11:49:14,988] Start new event
[2015-08-24 11:49:14,992] event 50
[2015-08-24 11:49:14,996] End event
[2015-08-24 11:49:15,000] Last log

```

I know that I can use a multiline pattern and flush\_pattern to parse the structured events learnt [here](https://www.elastic.co/guide/en/beats/filebeat/8.14/multiline-examples.html), but what about the first and last log then?

How should I go about using multiline and other techniques to parse this?

Any help is appreciated, thank you!
