# Multiline Pattern that starts with INFO|ERROR|WARN|DEBUG

**URL:** <https://discuss.elastic.co/t/multiline-pattern-that-starts-with-info-error-warn-debug/217698>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 3, 2020, 9:28pm UTC](https://discuss.elastic.co/t/multiline-pattern-that-starts-with-info-error-warn-debug/217698 "2020-02-03T21:28:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbwest](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbwest/32/32631_2.png) [@dbwest](https://discuss.elastic.co/u/dbwest)\
**Post date:** [February 3, 2020, 9:28pm UTC](https://discuss.elastic.co/t/multiline-pattern-that-starts-with-info-error-warn-debug/217698/1 "2020-02-03T21:28:47Z")

</div>

I want to match the following multiline log entry and others that start with INFO, WARN, or DEBUG

```auto
ERROR 2020-02-03 11:24:25,803 [[stuff-1.0.0-FILLER-some-domain].http.requester.HTTP_Request_configuration_Something.01 SomeRunner] [event: 2-a2649080-46a1-11ea-9700-00505693916f] org.klass.runtime.core.internal.exception.OnErrorPropagateHandler: 
********************************************************************************
Message : HTTP POST on resource 'https://esbmdl.grangeinsurance.com:443/api/qa/v1/someapp/documents/Some_Docs' failed: bad request (400).
Error type : HTTP:BAD_REQUEST
Element : someSubflow/processors/2 @ some-upload-doc-prc:upload-content.xml:12 (/someapp/documents/{itemTypeName})
Element XML : <http:request method="POST" doc:name="/someapp/documents/{itemTypeName}" doc:id="a44399ff-3685-4f43-ba08-156804cdaad4" config-ref="HTTP_Request_configuration_Someconfig" path="/documents/{itemTypeName}">
<http:uri-params>#[output application/java
---
{
	"itemTypeName" : vars.requestPayload.ItemType
}]</http:uri-params>
</http:request>

  (set debug level logging or '-Dmule.verbose.exceptions=true' for everything)
********************************************************************************

```

How do I do this?

This did not seem to work:

```auto
  multiline.pattern: '^(INFO|WARN|DEBUG|ERROR)'
  multiline.negate: true
  multiline.match: after

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 9:28pm UTC](https://discuss.elastic.co/t/multiline-pattern-that-starts-with-info-error-warn-debug/217698/2 "2020-03-02T21:28:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
