# Filebeat exclude line not working :(

**URL:** <https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 27, 2017, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358 "2017-12-27T19:47:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![funtimes](https://avatars.discourse-cdn.com/v4/letter/f/f08c70/32.png) [@funtimes](https://discuss.elastic.co/u/funtimes)\
**Post date:** [December 27, 2017, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/1 "2017-12-27T19:47:40Z")

</div>

Hello all! I've tried doing the best I can and research on my issue, however everything i've tried and research doesn't seem to work ☹

Was hoping somebody on here might be able to help me out.

I have a very simple webserver(remote) using nginx and filebeats(6.1) to ship the logs directly to ES/Kibana(6.1) box in my network.

The logs are getting there just fine, I just simply want to reduce some of the logs that are sent, as they are junk/filler logs that I do not want to parse/store in ES.

Below is an example of the nginx line i want to exclude

```
xxx.xxx.xxx.xxx - - [27/Dec/2017:05:57:06 -0500] "GET /feedback/user HTTP/1.1" 200 824 "https://website/page" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36"

```

Below is my nginx.yml config

```auto
- module: nginx
  access:
    enabled: true
    var.paths:
      - /var/log/nginx/access.log
    exclude_lines: ['feedback']
  error:
    enabled: true
    var.paths:
      - /var/log/nginx/error.log

```

Is there something that I am missing?

---

<div class="post-metadata">

**Author:** ![robscott27](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@robscott27](https://discuss.elastic.co/u/robscott27)\
**Post date:** [December 27, 2017, 9:38pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/2 "2017-12-27T21:38:22Z")

</div>

I ran into this same issue last week and never got a response, but I did find a work around. It doesn't hold through package updates though since the files get overwritten. Not sure if this will help you, but here's the topic I opened:

> [@Exclude\_lines regex isn't working](https://discuss.elastic.co/t/exclude-lines-regex-isnt-working/112723):
>
> I'm trying to exclude lines from apache log that contain /server-status?auto= within the line. It's a standard apache combined log file. exclude\_lines expressions I've tried: ['(?i:/server-status?auto=)'] ['.server-status.'] ['GET /server-status'] as well as a few other iterations I can't remember along the way. I even tried ['.'] and ['\*'] in order to trigger excluding EVERYTHING in the log just to make sure it was actually processing but neither of those had any effect and the logs still…

---

<div class="post-metadata">

**Author:** ![funtimes](https://avatars.discourse-cdn.com/v4/letter/f/f08c70/32.png) [@funtimes](https://discuss.elastic.co/u/funtimes)\
**Post date:** [December 27, 2017, 9:52pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/3 "2017-12-27T21:52:26Z")

</div>

@robscott27 You are awesome!!!!!

I followed your example for the nginx config file at

```auto
/usr/share/filebeat/module/nginx/access/config/nginx-access.yml

```

Added this last line to the bottom

```auto
type: log
paths:
{{ range $i, $path := .paths }}
 - {{$path}}
{{ end }}
exclude_files: [".gz$"]
exclude_lines: ['.*feedback.*']

```

And now it works as expected!!!! Thank you so much!! Wish I would have found that post earlier! Have been beating my head against the wall for days.

---

<div class="post-metadata">

**Author:** ![robscott27](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@robscott27](https://discuss.elastic.co/u/robscott27)\
**Post date:** [December 27, 2017, 11:09pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/4 "2017-12-27T23:09:38Z")

</div>

Just remember that if/when you update the filebeat package, those changes  
will not persist. They will be overwritten when the package is updated. I  
can confirm this is the case when I updated from 6.1.0 to 6.1.1.

As mentioned, this is not the best way to get the exclusions working and I  
never heard from anyone in that topic post as to why those config files  
aren't being read/processed. Good to know it's not just me running into  
this!

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 29, 2017, 2:01am UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/5 "2017-12-29T02:01:32Z")

</div>

The exclude\_lines should also be prefixed with `var` I think, then it should work.

---

<div class="post-metadata">

**Author:** ![funtimes](https://avatars.discourse-cdn.com/v4/letter/f/f08c70/32.png) [@funtimes](https://discuss.elastic.co/u/funtimes)\
**Post date:** [December 29, 2017, 2:14am UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/6 "2017-12-29T02:14:35Z")

</div>

> <https://github.com/elastic/beats/blob/master/filebeat/filebeat.reference.yml#L297>

So is line 297 in the file `filebeat.reference.yml` incorrect?

#exclude\_lines: ['^DBG']

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 3, 2018, 11:13pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/7 "2018-01-03T23:13:43Z")

</div>

My above comment should have said prefixed by `prospector` and not `var`.

About the file you linked: There is a difference between configuring a prospector and a module. A module is using a prospector but has some predefined config options for the specific module. So from the module you need to use the `prospector` prefix to access the prospector config options.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2018, 11:13pm UTC](https://discuss.elastic.co/t/filebeat-exclude-line-not-working/113358/8 "2018-01-31T23:13:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
