# GROK filter throws ERROR

**URL:** <https://discuss.elastic.co/t/grok-filter-throws-error/143424>\
**Category:** Logstash\
**Created:** [August 8, 2018, 5:04am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424 "2018-08-08T05:04:19Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 6:39am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/5 "2018-08-08T06:39:32Z")

</div>

As you have suggest in [Multiline issue with 2 different patterns for a single event](https://discuss.elastic.co/t/multiline-issue-with-2-different-patterns-for-a-single-event/57896/5) I have put :

```
beats {
	port=>5044
	multiline {
	  pattern => "^%{TIMESTAMP_ISO8601}"
	  negate => true
	  what => "previous"
	}
}

```

and in the beginning of filter before anything I have put :

`overwrite => ["message"]`

should this configuration work for parsing.

---

_[View the full topic](https://discuss.elastic.co/t/grok-filter-throws-error/143424)._
