# Multiline - pattern repeats in content

**URL:** <https://discuss.elastic.co/t/multiline-pattern-repeats-in-content/116113>\
**Category:** Logstash\
**Created:** [January 18, 2018, 6:01pm UTC](https://discuss.elastic.co/t/multiline-pattern-repeats-in-content/116113 "2018-01-18T18:01:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vanian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vanian/32/16235_2.png) [@vanian](https://discuss.elastic.co/u/vanian)\
**Post date:** [January 18, 2018, 6:01pm UTC](https://discuss.elastic.co/t/multiline-pattern-repeats-in-content/116113/1 "2018-01-18T18:01:17Z")

</div>

Hello, I'm using Logstash to parse some incident reports and attempting to use the multiline codec with my CSV files. The problem I'm running into is that in certain fields, the pattern that I'm using to determine a new event is repeated in the text. This is breaking the flow and causing errors:

`<CSV::MalformedCSVError: Illegal quoting in line 1.>`

Each event starts with an ID, like this:

`IM00103411`

...and here is my configuration file:

```
codec => multiline {
			pattern => "^IM00"
			negate => "true"
			what => "previous"

```

Any suggestions on how I can avoid tripping up on this copy and breaking out of the multiline magic too early? Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2018, 6:01pm UTC](https://discuss.elastic.co/t/multiline-pattern-repeats-in-content/116113/2 "2018-02-15T18:01:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
