# Optional \<feff\> on start of multiline pattern

**URL:** <https://discuss.elastic.co/t/optional-feff-on-start-of-multiline-pattern/80387>\
**Category:** Logstash\
**Created:** [March 28, 2017, 11:14pm UTC](https://discuss.elastic.co/t/optional-feff-on-start-of-multiline-pattern/80387 "2017-03-28T23:14:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [March 28, 2017, 11:14pm UTC](https://discuss.elastic.co/t/optional-feff-on-start-of-multiline-pattern/80387/1 "2017-03-28T23:14:41Z")

</div>

> \< f e f f \>[20170328,

I have log lines coming from an application that start normally with "[YYYYMMdd," which is easy to put into a multiline pattern, but occasionally there is a \< f e f f \> at the front of line.

I have tried

> codec =\> multiline { pattern =\> "^[|^\< f e f f \>[" negate =\> true what =\> previous }

but to no avail. Is there a way to get this BOM to start a multiline pattern or even better a pattern that will allow it as an optional character?

Ignore the spaces in the eff e eff eff string as when I don't have them the editor translates it to a non-visible character.

thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 11:14pm UTC](https://discuss.elastic.co/t/optional-feff-on-start-of-multiline-pattern/80387/2 "2017-04-25T23:14:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
