# Why multiline pattern merge lines that don't respect the regex?

**URL:** <https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 21, 2021, 11:07am UTC](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656 "2021-05-21T11:07:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![syrine\_chelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syrine_chelly/32/84013_2.png) [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Post date:** [May 21, 2021, 11:07am UTC](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656/1 "2021-05-21T11:07:55Z")

</div>

i want my filebeat.yml to combine only the lines that respect the regex  
multiline.pattern: '^Server [[:graph:]]\* Line'

multiline.negate: true

multiline.match: after  
but actually it combines the other lines that don't even contain the world server.and this not waht i want ?  
this is my filebeat.yml

```auto
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: log

  # Change to true to enable this input configuration.

  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.

  paths:

    - C:\elasticstack\filebeat-7.10.2-windows-x86_64\filebeat-7.10.2-windows-x86_64\logs\*.log

  #ignore_older: 5m

  #close_inactive: 2m

    #- c:\programdata\elasticsearch\logs\*

  #exclude_lines: ['^\(', '^[[:space:]]', ^Script , ^bde_ , ^CHEMIN]

  include_lines: ['^(3[01]|0[1-9]|[12][0-9])(-?)(1[0-2]|0[1-9])(-?)([0-9]{4})[[:space:]]([0-9]{2}):([0-9]{2}):([0-9]{2})', 'ETAPE','ERREUR INTERNE']

  multiline.pattern: '^Server [[:graph:]]* Line'

  multiline.negate: true

  multiline.match: after

```

what's the problem exctly ?

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 24, 2021, 7:57am UTC](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656/2 "2021-05-24T07:57:58Z")

</div>

The property `multiline.negate: true` means that you want to use the negated pattern.

---

<div class="post-metadata">

**Author:** ![syrine\_chelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syrine_chelly/32/84013_2.png) [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Post date:** [May 24, 2021, 9:12am UTC](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656/3 "2021-05-24T09:12:20Z")

</div>

i want to understand why it merges the other lines in file log which doesn't respect the regex.I want only to merge the lines which respect the regex did you get my point ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2021, 11:13am UTC](https://discuss.elastic.co/t/why-multiline-pattern-merge-lines-that-dont-respect-the-regex/273656/4 "2021-06-21T11:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
