# Filebeat exclude lines not working

**URL:** <https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 13, 2018, 6:07am UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879 "2018-07-13T06:07:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![HerberthObregon](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@HerberthObregon](https://discuss.elastic.co/u/HerberthObregon)\
**Post date:** [July 13, 2018, 6:07am UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879/1 "2018-07-13T06:07:13Z")

</div>

Filebeats  
does not exclude the lines as I expected

my configuration is

> ```
> filebeat.prospectors:
> - type: log
> enabled: true
> paths:
> - /var/log/*.log
> exclude_lines: ['.js','.png','.svg','.json','.txt']
> #also i try
> exclude_lines: ['.*\.(js|svg|png|json|txt).*']
> 
> ```

in /etc/filebeat/filebeat.yml

but keep creating documents in ES

![Captura%20de%20pantalla%20de%202018-07-13%2000-04-46](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1b41b721123cae48d90d372a8806e0e73321d59c.png)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [July 13, 2018, 10:25am UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879/2 "2018-07-13T10:25:00Z")

</div>

Hi @HerberthObregon and welcome 🙂

Indeed your regular expression looks fine, but are these logs being read from `/var/log/*.log`? It looks like you are using the nginx module. Modules include their own prospector configurations, so your filebeat is probably not using this `exclude_lines` setting for the nginx logs.

Something you can try is to add a [`drop_event`](https://www.elastic.co/guide/en/beats/filebeat/6.3/drop-event.html) processor, that allows you to filter on the already parsed log lines, in your case I guess it'd be something like this:

```auto
processors:
  drop_event.when.regexp:
    nginx.access.url: '.*\.(js|svg|png|json|txt)$'

```

---

<div class="post-metadata">

**Author:** ![HerberthObregon](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@HerberthObregon](https://discuss.elastic.co/u/HerberthObregon)\
**Post date:** [July 13, 2018, 12:39pm UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879/3 "2018-07-13T12:39:39Z")

</div>

> [@jsoriano](#):
>
> but are these logs being read from `/var/log/*.log` ?

There are several folders but among them is that of nginx and there is actually the log there

> [@jsoriano](#):
>
> ```auto
> processors:
> drop_event.when.regexp:
> nginx.access.url: '.*\.(js|svg|png|json|txt)$'
> 
> ```

y try add this to end of the file `/etc/filebeat/filebeat.yml`

then I run `sudo service filebeat restart`

I drop filebeat-\* Index in ES

I go to Kibana and check but still create docs with .js files logs ☹

I have already searched the internet and I have not found how to send this behavior, the reason for this is that I only want to monitor my API and not my static files  
You are my last hope to achieve this ☹

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [July 13, 2018, 1:03pm UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879/4 "2018-07-13T13:03:20Z")

</div>

Could you also paste the configuration of the nginx module?

What are the paths of your nginx log files?

---

<div class="post-metadata">

**Author:** ![HerberthObregon](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@HerberthObregon](https://discuss.elastic.co/u/HerberthObregon)\
**Post date:** [July 14, 2018, 9:12am UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879/5 "2018-07-14T09:12:04Z")

</div>

my logs is like a

```auto
0.0.0.0 - - [14/Jul/2018:06:27:41 +0000] "GET /static/js/c2log.js HTTP/1.1" 200 1675 "https://www.example.com/" "Mozilla/5.0 (Linux; Android 5.0.1; SM-N915V Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Mobile Safari/537.36"
0.0.0.0 - - [14/Jul/2018:06:27:41 +0000] "GET /static/js/rebound.js HTTP/1.1" 200 16594 "https://www.example.com/" "Mozilla/5.0 (Linux; Android 5.0.1; SM-N915V Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Mobile Safari/537.36"
0.0.0.0 - - [14/Jul/2018:06:27:41 +0000] "GET /static/js/qrcode.min.js HTTP/1.1" 200 20413 "https://www.example.com/" "Mozilla/5.0 (Linux; Android 5.0.1; SM-N915V Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Mobile Safari/537.36"
0.0.0.0 - - [14/Jul/2018:06:27:41 +0000] "GET /static/values/world.js HTTP/1.1" 200 14691 "https://www.example.com/" "Mozilla/5.0 (Linux; Android 5.0.1; SM-N915V Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Mobile Safari/537.36"
0.0.0.0 - - [14/Jul/2018:06:27:41 +0000] "GET /static/values/countries.js HTTP/1.1" 200 296755 "https://www.example.com/" "Mozilla/5.0 (Linux; Android 5.0.1; SM-N915V Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Mobile Safari/537.36"

```

and my config in `/usr/share/filebeat/module/nginx/access/config/nginx-access.yml`

```auto
type: log
paths:
{{ range $i, $path := .paths }}
 - {{$path}}
{{ end }}
exclude_files: [".gz$"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2018, 9:12am UTC](https://discuss.elastic.co/t/filebeat-exclude-lines-not-working/139879/6 "2018-08-11T09:12:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
