# Only Multiline lines that \*do\* match

**URL:** <https://discuss.elastic.co/t/only-multiline-lines-that-do-match/142941>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 3, 2018, 3:49pm UTC](https://discuss.elastic.co/t/only-multiline-lines-that-do-match/142941 "2018-08-03T15:49:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![widhalmt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/widhalmt/32/8237_2.png) [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Post date:** [August 3, 2018, 3:49pm UTC](https://discuss.elastic.co/t/only-multiline-lines-that-do-match/142941/1 "2018-08-03T15:49:18Z")

</div>

Hi,

I have a log like this:

```auto
2018-08-03 xxx
# yyy
# yyy
# yyy
2018-08-03 xxx

```

I need help with filebeat demultilining this log. I need all events starting with a number in a single line, but I need all lines from a block starting with `#` in one event.

My problem is that all multiline mechanics of filebeat will use one of the lines with the timestamp as first or last line of the multiline event. This is _not_ what I need. In fact, lines starting with a timestamp and logs starting with `#` should, in my opinion, be put into different logfiles but I won't be able to change it.

Can anyone give me a hint? Am I just blind or is this really not possible with the current options.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2018, 3:49pm UTC](https://discuss.elastic.co/t/only-multiline-lines-that-do-match/142941/2 "2018-08-31T15:49:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
