# Multiline issue with 2 different patterns for a single event

**URL:** <https://discuss.elastic.co/t/multiline-issue-with-2-different-patterns-for-a-single-event/57896>\
**Category:** Logstash\
**Created:** [August 12, 2016, 8:16am UTC](https://discuss.elastic.co/t/multiline-issue-with-2-different-patterns-for-a-single-event/57896 "2016-08-12T08:16:22Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![jinal.shah](https://avatars.discourse-cdn.com/v4/letter/j/3da27b/32.png) [@jinal.shah](https://discuss.elastic.co/u/jinal.shah)\
**Post date:** [August 12, 2016, 11:42am UTC](https://discuss.elastic.co/t/multiline-issue-with-2-different-patterns-for-a-single-event/57896/5 "2016-08-12T11:42:15Z")

</div>

At the moment, I'm just running it manually via STDIN and observing the output on STDOUT while I test that the configuration works OK.

This is the full test configuration I am using to test that the parsing:

```
input { stdin { } }

    filter {

            grok {
                            match => { "message" => "\A%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:loglevel}%{SPACE}%{SYSLOG5424PRINTASCII:thread}%{SPACE}%{JAVACLASS:logger}%{SPACE}\[%{JAVAMETHOD:method}:%{NUMBER:line}]%{SPACE}-%{SPACE}%{GREEDYDATA:message}" }
                            overwrite => ["message"]
                    }
                    date {
                            match => ["timestamp", "MMM dd YYY HH:mm:ss", "MMM d YYY HH:mm:ss", "ISO8601"]
                            remove_field => ["timestamp"]
                    }
            multiline {
                    pattern => "^%{TIMESTAMP_ISO8601}"
                    negate => true
                    what => "previous"
            }
    }

    output {
      stdout { codec => rubydebug }
    }

```

And then manually running it with: /bin/logstash -f ../testconfigs/multiline.conf

---

_[View the full topic](https://discuss.elastic.co/t/multiline-issue-with-2-different-patterns-for-a-single-event/57896)._
