# Auditbeat Bug? - Include\_files not limiting to just those files

**URL:** https://discuss.elastic.co/t/auditbeat-bug-include-files-not-limiting-to-just-those-files/237798
**Category:** Beats
**Tags:** auditbeat
**Created:** [June 19, 2020, 11:35am UTC](https://discuss.elastic.co/t/auditbeat-bug-include-files-not-limiting-to-just-those-files/237798 "2020-06-19T11:35:04Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)
#### Post date: [June 19, 2020, 11:35am UTC](https://discuss.elastic.co/t/auditbeat-bug-include-files-not-limiting-to-just-those-files/237798/1 "2020-06-19T11:35:05Z")

</div>

The auditbeat reference documentation and common sense would imply that doing something like

- module: file\_integrity  
paths:
  - C:/windows/system32  
include\_files: ['(?i).dll$', '(?i).exe$']

would monitor ONLY .dll and .exe files in the system32 directory. Yet this config monitors all the files in system32. It is not limiting it to just dll and exe's. Is this how this was designed? Why can't elastic provide some useful, real-world examples in [https://www.elastic.co/guide/en/beats/auditbeat/master/auditbeat-module-file\_integrity.html](https://www.elastic.co/guide/en/beats/auditbeat/master/auditbeat-module-file_integrity.html)? 5 or 6 common examples, such as what I am trying to do, would make their products 100x clearer.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 17, 2020, 1:35pm UTC](https://discuss.elastic.co/t/auditbeat-bug-include-files-not-limiting-to-just-those-files/237798/2 "2020-07-17T13:35:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
