# Multiline pattern not working in my filebeat configuration

**URL:** <https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 1, 2020, 5:30pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588 "2020-03-01T17:30:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sushil](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@sushil](https://discuss.elastic.co/u/sushil)\
**Post date:** [March 1, 2020, 5:30pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588/1 "2020-03-01T17:30:42Z")

</div>

```
Hi ,

```

I am using below multiline option in my filebeat.yml file.

multiline.pattern: '^[[:space:]]+(at|.{3})\b|^Caused by:'  
multiline.negate: false  
multiline.match: after`Preformatted text`

but the logs are still printing in different lines in kibana.

Logs:-

Exception in thread "main" java.lang.IllegalStateException: A book has a null property  
at com.example.myproject.Author.getBookIds(Author.java:38)  
at com.example.myproject.Bootstrap.main(Bootstrap.java:14)  
Caused by: java.lang.NullPointerException  
at com.example.myproject.Book.getId(Book.java:22)  
at com.example.myproject.Author.getBookIds(Author.java:35)  
... 1 more

Kibana snap:-

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4d1d910f83c03c828de0eacf72d800dd89df67da.png)

please help resolve.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [March 3, 2020, 2:05pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588/2 "2020-03-03T14:05:04Z")

</div>

Hi,

I don't know if this helps but we use the follwoing config for Java Logs:  
multiline.pattern: ^\d?\d.\d\d.\d\d  
multiline.negate: true  
multiline.match: after

Where the pattern is the date format for the logs. This way, all lines starting with a date are separate entries while any other lines(like stacktraces) are appended to the previous entry.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2020, 2:05pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-working-in-my-filebeat-configuration/221588/3 "2020-03-31T14:05:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
