# Multiline for Logline starting with "STATUS" or "INFO"

**URL:** <https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 6, 2020, 6:13pm UTC](https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761 "2020-04-06T18:13:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 6, 2020, 6:13pm UTC](https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761/1 "2020-04-06T18:13:22Z")

</div>

I have some logs whose one word starts with "STATUS" or "INFO" and in my multline pattern, I want to identify these words as starting point. WHat will be the multiline? I tried

```auto
multiline.pattern: '^%{WORD}'

```

Sample Logs are below -

```auto
STATUS | wrapper | 2019/12/03 05:18:27 | --> Wrapper Started as Service 
INFO | jvm 832 | 2020/02/25 09:00:04 | at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) ~[na:1.8.0_181]
INFO | jvm 2 | 2020/03/25 12:36:32 | 2020-03-25 12:36:32,291 INFO [WrapperSimpleAppMain] o.s.web.context.ContextLoader - Root WebApplicationContext: initialization started

```

I saw that in some examples when log doesnt start from date or timestamp, we can give a customized pattern like this-

```auto
multiline:
        pattern: 'wordwewanttostartsentencefrom: Identifier$'
        negate: true
        match: after

```

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 7, 2020, 3:57am UTC](https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761/2 "2020-04-07T03:57:40Z")

</div>

@steffens I read alot of your comments based on this topic. But none were where log line didnt start from timestamp. So could you please suggest.

@andrewkroh I also read your comment on post bellow and tried the method suggested there by replacing multiline.pattern: 'STATUS: Identifier$' but taht didnt work either. Please suggest multiline pattern for above log sample.

> [@Matching a word with filebeat multiline](https://discuss.elastic.co/t/matching-a-word-with-filebeat-multiline/62417/3):
>
> Looks like a duplicate of [http://stackoverflow.com/a/39899056/503798](http://stackoverflow.com/a/39899056/503798) which has a working answer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 3:57am UTC](https://discuss.elastic.co/t/multiline-for-logline-starting-with-status-or-info/226761/3 "2020-05-05T03:57:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
