# Mutiline pattern Filebeat

**URL:** <https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 29, 2017, 12:08pm UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277 "2017-06-29T12:08:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [June 29, 2017, 12:08pm UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/1 "2017-06-29T12:08:51Z")

</div>

Hello EveryOne,

I send data with filebeat and I want to use mutiline. Every event start with date like this :  
`2017-06-12T15:52:56.201_I_I_01de02a1ec3d0b28 [07:48] func will be continued(0,0000000001800094)`

In logstash I used the following pattern : `pattern => "^%{TIMESTAMP_ISO8601}"` But with filebeat it doesn't work. I used also this pattern : '^[0-9]{4}-[0-9]{2}-[0-9]{2}' but it doesn't work also.

Thank you for your help !

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 29, 2017, 12:17pm UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/2 "2017-06-29T12:17:09Z")

</div>

filebeat version?

can you share your config and sample log lines?

This go-playground can be used to test multiline patterns. Just update the 'pattern', 'negate' and 'content' variable and click 'Run'.

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [June 29, 2017, 12:35pm UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/3 "2017-06-29T12:35:10Z")

</div>

The filebeat version is 5.4.0.

My config :  
### Multiline options

```
  # Mutiline can be used for log messages spanning multiple lines. This is common
  # for Java Stack Traces or C-Line Continuation

  # The regexp Pattern that has to be matched. The example pattern matches all lines starting with [
  multiline.pattern: '^\[0-9]{4}-[0-9]{2}-[0-9]{2}' 
   #multiline.pattern: '^\['

  # Defines if the pattern set under pattern should be negated or not. Default is false.
  multiline.negate: true

  # Match can be set to "after" or "before". It is used to define if lines should be append to a pattern
  # that was (not) matched before or after or as long as a pattern is not matched based on negate.
  # Note: After is the equivalent to previous and before is the equivalent to to next in Logstash
  multiline.match: before

```

My log :

```
2017-06-12T15:52:56.201_I_I_01de02a1ec3d0b28 [09:05] >>>>>>>>>>>>resume interp(0), func:CallStrategy 
    _I_I_01de02a1ec3d0b28 [09:04] ASSIGN: iReturn(LOCAL) <- INTEGER: 0
    _I_I_01de02a1ec3d0b28 [09:04] ASSIGN: zVQGRP(LOCAL) <- STRING: "VQ_COFBE_OUTSOURCER_NL"
    _I_I_01de02a1ec3d0b28 [09:04] ASSIGN: iIteration(LOCAL) <- INTEGER: 2
    _I_I_01de02a1ec3d0b28 [09:04] ASSIGN: zTargetList(LOCAL) <- STRING: "COFBE_DEVELOPPEMENT_NL@StatServer_URS_COFBE.GA,COFBE_OUTSOURCER_NL@StatServer_URS_COFBE.GA"
    _I_I_01de02a1ec3d0b28 [09:04] ASSIGN: zTempo(LOCAL) <- STRING: "578"

2017-06-12T15:52:56.201 Int 22000 ##### EI_COFBE_SICRC04_GestionHO_SSTR-v8 - 01de02a1ec3d0b28 - Distribution : COFBE_070_NL_CIBLE : distribution sur : COFBE_DEVELOPPEMENT_NL@StatServer_URS_COFBE.GA,COFBE_OUTSOURCER_NL@StatServer_URS_COFBE.GA - Iteration : 2
    _I_I_01de02a1ec3d0b28 [10:0d] HERE IS SDATA: VQ_90_078_COM_NL@COFBE_StatServer_CCA - StatLoadBalance
```

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [June 30, 2017, 9:36am UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/4 "2017-06-30T09:36:27Z")

</div>

Someone could help ?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 30, 2017, 10:46am UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/5 "2017-06-30T10:46:06Z")

</div>

See go playground: [https://play.golang.org/p/Q9AP0A6c5A](https://play.golang.org/p/Q9AP0A6c5A)

You regular expression seems invalid (well, still compiles), as you did escape the `[` operator, such that is becomes a match on the `[` character.

Try with multiline pattern: `'^[0-9]{4}-[0-9]{2}-[0-9]{2}'`

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [June 30, 2017, 12:53pm UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/6 "2017-06-30T12:53:27Z")

</div>

It works Thank you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2017, 1:01pm UTC](https://discuss.elastic.co/t/mutiline-pattern-filebeat/91277/7 "2017-07-28T13:01:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
