# Filebeats Pattern now working as expected?

**URL:** <https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 5, 2019, 2:37pm UTC](https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931 "2019-03-05T14:37:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![justx](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@justx](https://discuss.elastic.co/u/justx)\
**Post date:** [March 5, 2019, 2:37pm UTC](https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931/1 "2019-03-05T14:37:28Z")

</div>

I am attempting to use a filebeats 5.1. One of the multi line patterns i am using is causing me alot of trouble and I am not seeing why, I was hoping yall could point me in the right direction.

What I am trying to use, seems pretty simple:  
- input\_type: log  
paths:  
- C:\ProgramData\logs\Error.log  
multiline.pattern: '^TIME:'  
multiline.negate: true  
multiline.match: after

The events look like:  
TIME: [02/19/2019 15:09:30]  
SEVERITY: Error  
ERROR CODE: 0x20010001  
DETAILS: Internal logic error.: Unable to determine OEM code from license.

TIME: [02/19/2019 15:09:30]  
SEVERITY: Error  
ERROR CODE: 0x20010001  
DETAILS: Internal logic error.: TerminateThread -\> Service Thread

I made sure there is no characters before the Time value.

When I run this pattern all events get stuffed in 1 message. It is not broken into 2 separate messages. If I create 3 log events, copy paste, it will stuff all 3 events into the same message. I am very puzzled as this same pattern is working on a different log file with the only difference is that the word Time is "Time" in the log file that is working but in the events that are not working the word time is "TIME". Any idea why such a simple pattern would work in one log but not in another?

Thank you for taking a look

---

<div class="post-metadata">

**Author:** ![justx](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@justx](https://discuss.elastic.co/u/justx)\
**Post date:** [March 5, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931/2 "2019-03-05T15:39:52Z")

</div>

I figured this out, the encoding was incorrect and caused the pattern to not be matched. I updated the encoding to utf-16 and the pattern worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filebeats-pattern-now-working-as-expected/170931/3 "2019-04-02T15:39:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
