# Cant get regex to exclude line to work

**URL:** <https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 2, 2017, 12:23am UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432 "2017-08-02T00:23:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Puk](https://avatars.discourse-cdn.com/v4/letter/p/ea5d25/32.png) [@Puk](https://discuss.elastic.co/u/Puk)\
**Post date:** [August 2, 2017, 12:23am UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/1 "2017-08-02T00:23:15Z")

</div>

Newbie to ELK Stack and Filebeat here. Managed to get log shipping from my linux hosts working fine and have 2x prospectors for my syslogs and secure logs as going to try filtering them in logstash differently.

Anyway, I have a service running on all servers (NRPE for Nagios) which puts syslog entries every couple of minutes which I don't want to include, but I cannot seem to get filebeat to exclude them. This is what I currently have.

```
- input_type: log
  paths:
    - /var/log/messages*
    - /var/log/syslog*
  exclude_files: [".gz$"]
  exclude_lines: ['.*nrpe.*', '.*Nrpe.*']
  multiline:
    pattern: "^\\s"
    match: after
  fields:
      logtype: syslog_data

```

I've also tried

```
exclude_lines: ['[nN]rpe']
exclude_lines: [(?i)nrpe]

```

Any ideas what I'm doing wrong?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [August 2, 2017, 8:46am UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/2 "2017-08-02T08:46:04Z")

</div>

Can you paste also an example log line created by NRPE?

---

<div class="post-metadata">

**Author:** ![Puk](https://avatars.discourse-cdn.com/v4/letter/p/ea5d25/32.png) [@Puk](https://discuss.elastic.co/u/Puk)\
**Post date:** [August 2, 2017, 9:08pm UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/3 "2017-08-02T21:08:27Z")

</div>

Here you go -

```
Aug 2 12:16:13 thisuser xinetd[16389]: START: nrpe pid=40975 from=::ffff:10.10.10.4
Aug 2 12:16:13 thisuser xinetd[16389]: EXIT: nrpe status=0 pid=40975 duration=0(sec)
Aug 2 12:17:09 thisuser xinetd[16389]: START: nrpe pid=41024 from=::ffff:10.10.10.4
Aug 2 12:17:09 thisuser xinetd[16389]: EXIT: nrpe status=0 pid=41024 duration=0(sec)

```

I was trying to do it on case insensitive just in case it ever changes.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [August 2, 2017, 9:38pm UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/4 "2017-08-02T21:38:17Z")

</div>

Seem to work fine in my tests with simply: `exclude_lines: ['nrpe']`

Can you try without the multiline config? I worry about the use of `"` there. Single quotes are less problematic when it comes to regexps.

---

<div class="post-metadata">

**Author:** ![Puk](https://avatars.discourse-cdn.com/v4/letter/p/ea5d25/32.png) [@Puk](https://discuss.elastic.co/u/Puk)\
**Post date:** [August 3, 2017, 12:04am UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/5 "2017-08-03T00:04:19Z")

</div>

Really odd. I tried with just the 'nrpe' as you suggested above and still doesn't pull it out. So I commented out the multiline sections and it still doesn't strip it out. Not sure what is happening.

I only had the multiline in as that was the default config for syslog from the filebeat/logstash side.

---

<div class="post-metadata">

**Author:** ![Puk](https://avatars.discourse-cdn.com/v4/letter/p/ea5d25/32.png) [@Puk](https://discuss.elastic.co/u/Puk)\
**Post date:** [August 3, 2017, 2:33am UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/6 "2017-08-03T02:33:16Z")

</div>

Correction - I have got it to work. I'm not sure why but on my test lab it wasn't filtering it out, but when I tried this with one of my live systems with just a single agent it filtered it out OK! I then tried with the below and that also worked filtering out multiple entires.

`exclude_lines: ['nrpe', 'bamboo', 'java.lang']`

Much appreciated! Have also knocked up a simple Ansible playbook to push this out and allow me to adjust the config on the fly 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2017, 2:33am UTC](https://discuss.elastic.co/t/cant-get-regex-to-exclude-line-to-work/95432/7 "2017-08-31T02:33:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
