# Exclude\_lines regex isn't working

**URL:** <https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 20, 2017, 9:44pm UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723 "2017-12-20T21:44:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![robscott27](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@robscott27](https://discuss.elastic.co/u/robscott27)\
**Post date:** [December 20, 2017, 9:44pm UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723/1 "2017-12-20T21:44:57Z")

</div>

I'm trying to exclude lines from apache log that contain /server-status?auto= within the line. It's a standard apache combined log file.

exclude\_lines expressions I've tried:

['(?i:/server-status?auto=)']  
['._server-status._']  
['GET /server-status']

as well as a few other iterations I can't remember along the way.

I even tried ['.'] and ['\*'] in order to trigger excluding EVERYTHING in the log just to make sure it was actually processing but neither of those had any effect and the logs still were being picked up/inserted into ES.

Like several other posters, it works in Go, but when put into the apache2.yml file, it doesn't. I've also got exclude\_files: [".gz$"] and in the debug logs, I can clearly see it excluding those files.

Example of a log line that I'd like to exclude:

[example.site.com:80](http://example.site.com:80) 192.168.0.1 - - [20/Dec/2017:10:18:37 -0500] "GET /server-status?auto= HTTP/1.1" 301 522 "-" "Go-http-client/1.1"

Any ideas what I'm missing?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![robscott27](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@robscott27](https://discuss.elastic.co/u/robscott27)\
**Post date:** [December 22, 2017, 2:40pm UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723/2 "2017-12-22T14:40:41Z")

</div>

I figured this one out. I noticed that even though I had commented out the exclude\_files line, it was still excluding the .gz log files, even though it shouldn't. So I went digging.

Turns out, there's an access.yml file located here:  
/usr/share/filebeat/module/apache2/access/config

which still had the exclude\_files option set to ignore the .gz files. Below that line, I added:  
exclude\_lines: ['._(?:server-status)._']

and restarted the service. Watched the log file, and bingo, lines are being dropped now.

Not sure why it's ignoring processing the apache2.yml file in /etc/filebeat/modules.d/ though.

So if anyone else is having trouble with the exclude\_lines: option in apache.2yml, try checking that other file location listed above.

Not sure that change will survive a package update, but it's a small one and is easy to put back if need be.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 28, 2017, 1:56am UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723/3 "2017-12-28T01:56:19Z")

</div>

If you want to overwrite config options for the prospector from `modules.d` you have to use you have to prefix it with `var`: [https://www.elastic.co/guide/en/beats/filebeat/current/specify-variable-settings.html](https://www.elastic.co/guide/en/beats/filebeat/current/specify-variable-settings.html)

---

<div class="post-metadata">

**Author:** ![robscott27](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@robscott27](https://discuss.elastic.co/u/robscott27)\
**Post date:** [December 28, 2017, 3:04am UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723/4 "2017-12-28T03:04:57Z")

</div>

So, by that reasoning, if I wanted to modify the exclude\_lines config  
option in the apache2.yml access section - which isn't set to anything in  
the modules.d location - I would add a line:

var.exclude\_lines: [pattern]

However, in practice the lines are not excluded and still show up in ES  
when using var.exclude\_lines in /etc/filebeat/modules.d/apache2.yml. Also,  
from what I can tell on this page:  
[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache2.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache2.html)

the only variable settings listed are var.paths for both the access and  
error areas of the module.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 3, 2018, 11:02pm UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723/5 "2018-01-03T23:02:09Z")

</div>

I'm sorry my comment above was wrong. I confused the `var` configs with the `prospector` configs. As `exclude_lines` is a prospector option, you need to add it under the prospector namespace: [https://www.elastic.co/guide/en/beats/filebeat/current/advanced-settings.html](https://www.elastic.co/guide/en/beats/filebeat/current/advanced-settings.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2018, 11:02pm UTC](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723/6 "2018-01-31T23:02:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
