# Audit Log Exclude by Origin / Principal

**URL:** <https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902>\
**Category:** Elasticsearch\
**Created:** [January 24, 2018, 5:10pm UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902 "2018-01-24T17:10:15Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![lask001](https://avatars.discourse-cdn.com/v4/letter/l/4da419/32.png) [@lask001](https://discuss.elastic.co/u/lask001)\
**Post date:** [January 25, 2018, 2:00am UTC](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902/4 "2018-01-25T02:00:36Z")

</div>

I found this thread: [Kibana automatic activity is flooding audit log](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413/10)

I haven't been able to get any of the combinations in that thread to work for me. I've tried things like:

`.*elastic*.*`, `.*principal=.elastic.,.*`, `.principal=\[elastic\].`, `.principal=\\[elastic\\].`, `.*principal=\[elastic\].*`

Any suggestions, or do you see what I'm missing?

---

_[View the full topic](https://discuss.elastic.co/t/audit-log-exclude-by-origin-principal/116902)._
