# Exclude\_files param not working

**URL:** <https://discuss.elastic.co/t/exclude-files-param-not-working/302803>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 20, 2022, 10:50am UTC](https://discuss.elastic.co/t/exclude-files-param-not-working/302803 "2022-04-20T10:50:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yyovchev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yyovchev/32/104583_2.png) [@yyovchev](https://discuss.elastic.co/u/yyovchev)\
**Post date:** [April 20, 2022, 10:50am UTC](https://discuss.elastic.co/t/exclude-files-param-not-working/302803/1 "2022-04-20T10:50:58Z")

</div>

Hello, I try to exclude only one log file from filebeat, but the records are still sent to Elasticsearch. Here is my /etc/filebeat/modules.d/nginx.yml file:

```auto

# Module: nginx
# Docs: https://www.elastic.co/guide/en/beats/filebeat/7.4/filebeat-module-nginx.html

- module: nginx
  # Access logs
  access:
    enabled: true
    exclude_files: ["/var/log/nginx/exlude.this.domain.com_access.log"]
    var.paths: ["/var/log/nginx/*access*.log"]
    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

  # Error logs
  error:
    enabled: true
    var.paths: ["/var/log/nginx/*error*.log"]

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

```

Can you help me? Thank you for your time!  
Best regards,

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [April 20, 2022, 4:05pm UTC](https://discuss.elastic.co/t/exclude-files-param-not-working/302803/2 "2022-04-20T16:05:15Z")

</div>

Hi @yyovchev ,

By default only `var.paths` is accepted as a configuration in the [Nginx module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-nginx.html).

However it is possible to override input settings as described here: [Override input settings | Filebeat Reference [8.1] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/advanced-settings.html)

In your config you missed the `input` key, it should be:

```nohighlight
- module: nginx
  # Access logs
  access:
    enabled: true
    var.paths: ["/var/log/nginx/*access*.log"]
    input:
        exclude_files: ["/var/log/nginx/exlude.this.domain.com_access.log"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2022, 6:06pm UTC](https://discuss.elastic.co/t/exclude-files-param-not-working/302803/3 "2022-05-18T18:06:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
