# Optional leading character on multine pattern

**URL:** <https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 26, 2017, 3:56pm UTC](https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920 "2017-01-26T15:56:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [January 26, 2017, 3:56pm UTC](https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920/1 "2017-01-26T15:56:06Z")

</div>

Hello.  
I am process log files with filebeats and have come across a format that starts a multi line mess that may or may not have a character before the timestamp.

eg.  
Normal: "[20170126,"  
New case: "[20170126,"

I was using the pattern below and am asking for help in modifying it to understand either pattern as starting a new multiline.

multiline:  
pattern: '^[[:digit:]]{4}[[:digit:]]{2}[[:digit:]]{2},'

thank you

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 27, 2017, 12:43am UTC](https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920/2 "2017-01-27T00:43:39Z")

</div>

not sure I'm missing something, but I see no difference in the `Normal` and the `New case` here. An optional match can be expressed with `<term>?` meaning, match zero or one time.

---

<div class="post-metadata">

**Author:** ![mhooper](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mhooper](https://discuss.elastic.co/u/mhooper)\
**Post date:** [January 27, 2017, 1:13pm UTC](https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920/3 "2017-01-27T13:13:54Z")

</div>

You're right Steffen. bad copy / paste.

Normal is `[20170126,`  
Optional case is `<feff>[20170126,`.

thank you for your suggestion despite my miscommunication.

after replying and same thing happening I understand. the optional text is disappearing in entry box here. It is \< f e f f \> (without spaces).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 27, 2017, 1:21pm UTC](https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920/4 "2017-01-27T13:21:31Z")

</div>

You can escape code using backtick or the `</>` button.

Sorry, have to ask again, so the optional is `<feff>[20170126,`? like is `<feff>` just one character?

Are you using windows? This looks like an utf16 BOM flag. The BOM flag normally appears at beginning of file only. Can you share your prospectors configuration?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2017, 1:21pm UTC](https://discuss.elastic.co/t/optional-leading-character-on-multine-pattern/72920/5 "2017-02-24T13:21:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
