# Please tell me why my filebeat multi-line pattern is not applicable

**URL:** <https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721>\
**Category:** Beats\
**Created:** [June 4, 2020, 9:42am UTC](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721 "2020-06-04T09:42:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![111349](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111349/32/69694_2.png) [@111349](https://discuss.elastic.co/u/111349)\
**Post date:** [June 4, 2020, 9:42am UTC](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721/1 "2020-06-04T09:42:11Z")

</div>

```
This is the harvester part of my file beat (version6.8)

I intend so that the multi-line pattern is applied if the beginning of the log is not an 8-digit number.

And if you encounter a log that starts with an 8-digit number, the multi-line pattern application ends.

```

''''  
-type: log  
enabled: true  
paths:  
- mylogpath  
multiline.pattern: "^[^0-9]{8}"  
multiline.negate: true  
multiline.match: after  
multiline.flush\_pattern: "^[0-9]{8}"  
''''

```
This is part of my log

20200604 101010101 log...\n
makdneislalwnrufoskqnrhdi \n
skckzjsnfjfozkwmrjfidis \n
skxkvignrndksoslqnrjfi \n
dkxovognrndjsisoakqmenrjdi \n
20200604 101010101 log... \n

I tried [[:digit]] instead of [0-9], but the result was the same.

```

But when I changed to \d, I couldn't try because of filebeat error.

Please help me what was wrong and what I missed Thank you

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 4, 2020, 2:58pm UTC](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721/2 "2020-06-04T14:58:09Z")

</div>

I don't think you need to configure `multiline.flush_pattern`. You should also change `multiline.pattern`.

The config above should work for your logs:

```auto
multiline.pattern: "^[0-9]{8}"
multiline.negate: true
multiline.match: after

```

---

<div class="post-metadata">

**Author:** ![111349](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111349/32/69694_2.png) [@111349](https://discuss.elastic.co/u/111349)\
**Post date:** [June 5, 2020, 12:55am UTC](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721/3 "2020-06-05T00:55:57Z")

</div>

Thank you very much for the answer,

but it seems to be a pattern that doesn't suit me.

What I want is to ignore the number log line starting with 8 digits, and I want to collect other things in a multi-line.

That's why you put flush.

Finally, I want to collect lines starting with 8 digits as a single line, and lines not starting with 8 digits as a multiline.

Can you help me ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2020, 2:55am UTC](https://discuss.elastic.co/t/please-tell-me-why-my-filebeat-multi-line-pattern-is-not-applicable/235721/4 "2020-07-03T02:55:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
