# Filebeat Multiline Start End pattern

**URL:** <https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 23, 2020, 10:51am UTC](https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442 "2020-04-23T10:51:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kishore419](https://avatars.discourse-cdn.com/v4/letter/k/b4bc9f/32.png) [@kishore419](https://discuss.elastic.co/u/kishore419)\
**Post date:** [April 23, 2020, 10:51am UTC](https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442/1 "2020-04-23T10:51:19Z")

</div>

Hello Team,

## I have to parse following log content using filebeat-multiline feature. Log file: Start value1

* * *

## End completed other data

## Start Value1

* * *

End completed

i want to capture the multline start with 'Start value1' End with 'End completed' and send as single event to Kafka(output plugin)  
Otherdata to be considered line by line and send to kafka

i could not see any example of start/stop with combination of Multilline  
i also found, this feature to be implemented (as per 2016 queries)  
is the above feature available in Filebeat-multiline?  
if yes, could you please share examples

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [April 23, 2020, 11:08am UTC](https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442/2 "2020-04-23T11:08:18Z")

</div>

hi @kishore419, does this help in your case ?[https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#\_application\_events](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html#_application_events).  
The `pattern` option specifies the beginning of an event, the `flush_pattern` option will specify the end or last line of the event.

---

<div class="post-metadata">

**Author:** ![kishore419](https://avatars.discourse-cdn.com/v4/letter/k/b4bc9f/32.png) [@kishore419](https://discuss.elastic.co/u/kishore419)\
**Post date:** [April 23, 2020, 11:45am UTC](https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442/3 "2020-04-23T11:45:53Z")

</div>

@MarianaD Thanks for Quick Reply. But this is not working as expected.  
can you please help

Log line:  
Start  
value 1  
value2  
End  
Value3  
value4

filbeat condition:

multiline.pattern: 'Start'  
multiline.negate: true  
multiline.match: after  
multiline.flush\_pattern: 'End'

**Expected Output:**  
**Event 1:**  
Start  
value 1  
value2  
End  
**Event 2:**  
value 3  
**Event 3:**  
value 4

Actual Output:  
**Event 1:**  
Start  
value 1  
value2  
End  
Value3  
value4

---

<div class="post-metadata">

**Author:** ![Leslie\_xxx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leslie_xxx/32/67845_2.png) [@Leslie\_xxx](https://discuss.elastic.co/u/Leslie_xxx)\
**Post date:** [May 7, 2020, 2:53am UTC](https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442/4 "2020-05-07T02:53:08Z")

</div>

@MarianaD

Same requirement and problem.

My output:

```auto
Event1:
Start
1
2
End

Event 2:
3
4

```

Expect output:

```auto
Event1:
START
1
2
END

event2
3

event3
4

```

Why 3 and 4 are include in one event? They're not incompatible multiline pattern and flush\_pattern。3 and 4 should individually by itself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 2:53am UTC](https://discuss.elastic.co/t/filebeat-multiline-start-end-pattern/229442/5 "2020-06-04T02:53:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
