# Filebeat - multiline pattern does not work as expected

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 10, 2018, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196 "2018-12-10T14:53:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mateusz-lubanski-omn](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@mateusz-lubanski-omn](https://discuss.elastic.co/u/mateusz-lubanski-omn)\
**Post date:** [December 10, 2018, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196/1 "2018-12-10T14:53:12Z")

</div>

Hi,

I set up multiline.\* properties for /etc/filebeat/filebeat.yml as bellow:  
filebeat.inputs:  
- type: log  
paths:  
- /home/eip/logs/\*.log  
tail\_files: true  
multiline.pattern: '^%{TIMESTAMP\_ISO8601}'  
multiline.negate: true  
multiline.match: after

Here sample how above configuration group logs

 ![multiline_problem](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6bb08affdb45ca669dfc541ad3f6556b1bccf49.jpeg)

Unfortunatelly filebeat does not group lines as expected and is groupping much more than is should.  
Is there maybe another configuration which cause the issue or is value of multiline.pattern property defined wrongly?

Thanks Mateusz

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 11, 2018, 2:15am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196/2 "2018-12-11T02:15:29Z")

</div>

Could you post a sample log file and an example of your desired grouping here? For posting the sample log file you might need to use something like [https://pastebin.com/](https://pastebin.com/) if it's too large. Once I have these I can do some experimentation to try and come up with the right multiline settings.

---

<div class="post-metadata">

**Author:** ![mateusz-lubanski-omn](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@mateusz-lubanski-omn](https://discuss.elastic.co/u/mateusz-lubanski-omn)\
**Post date:** [December 11, 2018, 8:54am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196/3 "2018-12-11T08:54:13Z")

</div>

Hi @shaunak

Sure, let me please provide more details.  
For logging we are using log4j with [ConversattionPattern](https://logging.apache.org/log4j/1.2/apidocs/org/apache/log4j/PatternLayout.html): %d [%t] %-5p - %m%n  
So sample loog look like: [https://pastebin.com/V1NnxMQc](https://pastebin.com/V1NnxMQc)

whenever line in log file starts with pattern "%d [%t] %-5p" defined by log4j filebeat should group next lines till pattern occur again. Expected multiline logs will look like:

- [https://pastebin.com/5qwB2pYY](https://pastebin.com/5qwB2pYY)
- [https://pastebin.com/Jr19cJjP](https://pastebin.com/Jr19cJjP)
- [https://pastebin.com/ez7ZNUJD](https://pastebin.com/ez7ZNUJD)

Thanks, Mateusz

---

<div class="post-metadata">

**Author:** ![mateusz-lubanski-omn](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@mateusz-lubanski-omn](https://discuss.elastic.co/u/mateusz-lubanski-omn)\
**Post date:** [December 11, 2018, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196/4 "2018-12-11T13:04:54Z")

</div>

Below pattern solved problem:  
multiline.pattern: '^\d{4}-\d{2}-\d{2} '

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2019, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern-does-not-work-as-expected/160196/5 "2019-01-08T13:04:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
