# Filebeat multiline pattern

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-pattern/251274>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, filebeat\
**Created:** [October 7, 2020, 1:10pm UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern/251274 "2020-10-07T13:10:22Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [October 8, 2020, 4:58am UTC](https://discuss.elastic.co/t/filebeat-multiline-pattern/251274/2 "2020-10-08T04:58:29Z")

</div>

Hi,

I guess the problem is that the first line of the stacktrace does not start with a space - it starts with a dash sign. There are multiple threads within this forum for multiline support (e.g. [Filebeat multiline regexp patterns help](https://discuss.elastic.co/t/filebeat-multiline-regexp-patterns-help/170648)). Please have a look there. In short:

- change the pattern to match your date-time at the start of the main line
- switch negate to true

Best regards  
Wolfram

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-multiline-pattern/251274)._
