# Filebeat Bug: exclude\_lines

**URL:** <https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 29, 2021, 8:15am UTC](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611 "2021-01-29T08:15:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Peter\_Boos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_boos/32/72670_2.png) [@Peter\_Boos](https://discuss.elastic.co/u/Peter_Boos)\
**Post date:** [January 29, 2021, 8:15am UTC](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611/1 "2021-01-29T08:15:03Z")

</div>

**BUG report**  
**filebeat version :** filebeat-7.10.1-2021.01.13-000001  
**problem :** The `exclude_lines` option in filebeat.yml does not work.

Example item to be filtered out :

```auto
2021-01-27T02:08:31.775-0500#011INFO#011log/harvester.go:302#011Harvester started for file: /var/log/syslog
2021-01-27T02:08:22.758-0500#011INFO#011log/harvester.go:333#011File is inactive: /var/log/syslog. Closing because close_inactive of 5m0s reached.

```

Tested all kinds regex syntax filters none works

```auto
# as : is used in regex i use . instead
exclude_lines: ['\bharvester/.go.333|\bharvester/.go.302']
exclude_lines: ['\bgo.333','\bgo.303','^DBG']
exclude_lines: ['.*go.333.*', '.*go.302.*', '^DBG']

```

\b first word pattern matching  
.\* any characters till pattern  
. any sungle character (replacing the : )

```auto
filebeat.inputs
- type: log
  enabled: true
  paths:
    - /var/log/*.log
  exlude_lines : # see all the above attempts none work

```

---

<div class="post-metadata">

**Author:** ![Peter\_Boos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_boos/32/72670_2.png) [@Peter\_Boos](https://discuss.elastic.co/u/Peter_Boos)\
**Post date:** [January 29, 2021, 10:51am UTC](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611/2 "2021-01-29T10:51:12Z")

</div>

While still a bug, and **please developers explain exclude\_lines** better  
I found an **unreliable?** work around that works for this case  
I still would prefer the other syntax using regex, but it doesnt work.  
I tried with when: regexp message:

```auto
processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~
  - drop_event:
      when:
        or:
          - contains.message: "harvester.go:302"
          - contains.message: "harvester.go:333"                                                                                                                

```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [January 29, 2021, 7:39pm UTC](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611/3 "2021-01-29T19:39:49Z")

</div>

302 and 333 are line numbers in the `harvester.go` file from where the log messages are being generated. It seems unreliable to refer to specific line numbers in the exclude pattern. In some future release these line numbers could change.

Without using specific line numbers could you explain what types of lines you are trying to exclude? Maybe there is a better expression we can come up with.

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 9:40pm UTC](https://discuss.elastic.co/t/filebeat-bug-exclude-lines/262611/4 "2021-02-26T21:40:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
