# Exclude\_line regex

**URL:** <https://discuss.elastic.co/t/exclude-line-regex/161645>\
**Category:** Beats\
**Created:** [December 20, 2018, 9:05am UTC](https://discuss.elastic.co/t/exclude-line-regex/161645 "2018-12-20T09:05:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Miguel\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_leite/32/41988_2.png) [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Post date:** [December 20, 2018, 9:05am UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/1 "2018-12-20T09:05:21Z")

</div>

`NetState	47880	2018/12/20 08:44:02.422	StateManagerComponent	ERROR - ProcessConfirmBlock - Unknown blockUid`

Does anyone know how to match by regex:

```
StateManagerComponent	ERROR - ProcessConfirmBlock - Unknown blockUid
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 27, 2018, 1:26pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/2 "2018-12-27T13:26:39Z")

</div>

If you know it's this plain string you want to match against, just add the string as is to the `exclude_lines` setting.

---

<div class="post-metadata">

**Author:** ![Miguel\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_leite/32/41988_2.png) [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Post date:** [December 28, 2018, 10:00am UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/3 "2018-12-28T10:00:56Z")

</div>

I did, but Filebeat doesn't seem to recognize it. As it doesn't exclude this line:

`exclude_lines: ['.*TRANSIENT_ConnectFailed.*']`

This log line won't get excluded:

`CORBA Exception is: name="TRANSIENT" minorCode=1096024066 minorCodeString="TRANSIENT_ConnectFailed" completed=NO`

---

<div class="post-metadata">

**Author:** ![Miguel\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_leite/32/41988_2.png) [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Post date:** [December 28, 2018, 2:28pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/4 "2018-12-28T14:28:00Z")

</div>

The exclude\_lines of my last post only works if none other exclude lines are used... What am I supposed to do? I have over 50 strings that I want to exclude, but I can't make it work for all of them.

Any suggestions? This exclude\_lines configuration is killing me...

Thanks!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 2, 2019, 1:08pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/5 "2019-01-02T13:08:54Z")

</div>

Do you have some more complete sample?

I think it should work, unless you have some accidental overlap. When exclude\_lines is configured each pattern is checked against the line. If one matches, then the line is dropped.

so to make it a little more readable/manageable better use list syntax:

```auto
filebeat.inputs:
- type: log
  ...
  exclude_lines:
  - 'TRANSIENT_ConnectFailed' # no need for .*
  - '<pattern2>'
  - '<pattern3>'

```

---

<div class="post-metadata">

**Author:** ![Miguel\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_leite/32/41988_2.png) [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Post date:** [January 4, 2019, 3:07pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/6 "2019-01-04T15:07:12Z")

</div>

Is it possible to use the list syntax with more than one pattern per line?

It is working with the list syntax! Thanks!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 4, 2019, 3:21pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/7 "2019-01-04T15:21:36Z")

</div>

> [@Miguel\_Leite](#):
>
> Is it possible to use the list syntax with more than one pattern per line?

Unfortunately not. If two patterns are very similar one can use an or expression like: `- '(regex1)|(regex2)'` or `- '^common start ((regex1)|(regex2)) more common pattern'`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2019, 5:21pm UTC](https://discuss.elastic.co/t/exclude-line-regex/161645/8 "2019-02-01T17:21:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
