# Exclude\_files doesn't work?

**URL:** <https://discuss.elastic.co/t/exclude-files-doesnt-work/109799>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 30, 2017, 5:08pm UTC](https://discuss.elastic.co/t/exclude-files-doesnt-work/109799 "2017-11-30T17:08:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![przemolb](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@przemolb](https://discuss.elastic.co/u/przemolb)\
**Post date:** [November 30, 2017, 5:08pm UTC](https://discuss.elastic.co/t/exclude-files-doesnt-work/109799/1 "2017-11-30T17:08:01Z")

</div>

Hi,  
I have the following in my filebeat.yml (5.6):  
...  
exclude\_files: ['.gz$', 'btmp\*', 'btmp$']  
...  
but filebeat says in its logs:  
`2017-11-30T17:03:07Z INFO Harvester started for file: /var/log/wtmp 2017-11-30T17:03:07Z INFO Harvester started for file: /var/log/lastlog 2017-11-30T17:03:07Z INFO Harvester started for file: /var/log/file.log-20171101.gz 2017-11-30T17:03:07Z INFO Harvester started for file: /var/log/btmp 2017-11-30T17:03:07Z INFO Harvester started for file: /var/log/btmp-20171101`  
Why it is reading btmp and \*.gz files ?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 30, 2017, 5:54pm UTC](https://discuss.elastic.co/t/exclude-files-doesnt-work/109799/2 "2017-11-30T17:54:55Z")

</div>

Could you share your whole config and filebeat logs? Please format it using `</>`.

---

<div class="post-metadata">

**Author:** ![przemolb](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@przemolb](https://discuss.elastic.co/u/przemolb)\
**Post date:** [December 1, 2017, 10:52am UTC](https://discuss.elastic.co/t/exclude-files-doesnt-work/109799/3 "2017-12-01T10:52:48Z")

</div>

Here you are:

```auto
    filebeat.prospectors:
    - input_type: log
      paths:
        - /var/log/*
      fields:
        type: system
    - input_type: log
      paths:
        - /opt/apps/logs/*.log
      fields:
        type: corda
      exclude_files: ['\.gz$', 'btmp*', 'btmp$']
    output.logstash:
      hosts: ["x.x.x.x:5043"]

```

---

<div class="post-metadata">

**Author:** ![przemolb](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@przemolb](https://discuss.elastic.co/u/przemolb)\
**Post date:** [December 1, 2017, 10:56am UTC](https://discuss.elastic.co/t/exclude-files-doesnt-work/109799/4 "2017-12-01T10:56:51Z")

</div>

For forum requirements I have removed all the original comments from filebeat.yml and now I can see why it doesn't work - there is missing `exclude_files` for the first `input_type`.  
So many years with config files and still ... 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 10:57am UTC](https://discuss.elastic.co/t/exclude-files-doesnt-work/109799/5 "2017-12-29T10:57:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
