# Filebeat : how to exclude lines

**URL:** <https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 24, 2021, 7:39am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306 "2021-08-24T07:39:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![thomas7467](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@thomas7467](https://discuss.elastic.co/u/thomas7467)\
**Post date:** [August 24, 2021, 7:39am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/1 "2021-08-24T07:39:26Z")

</div>

Hi,  
Using ELK 7.14.0 release.  
I'm trying to excludes lines from IIS access log files. I've tried several methods but It still will not work.  
I've done that previously with logstash, but I prefer use a simplified architecture.

Last try was to include the following line in filebeat.yml:

```auto
processors:
   - drop_event:
     when.equals.http.request.method: OPTIONS

```

I'm tryng to exclude healthcheck lines like these:

2021-05-25 00:03:31 W3SVC2 prewww3 172.25.50.72 OPTIONS / - 80 - 172.25.50.123 HTTP/1.0 - - - - 200 0 0 226 22 2 -

Thanks for help,  
Thomas

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 24, 2021, 7:45am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/2 "2021-08-24T07:45:04Z")

</div>

Have you tried the exclude\_lines options on the input?  
I'm using that since Version 5 to exclude some nonsensical lines (empty lines and separator lines) in our logs.

```auto
filebeat.inputs:
- type: log
  exclude_lines: ["^-*$", "^$"]
...

```

> **[Log input | Filebeat Reference \[7.14\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-exclude-lines)**

For your case it would probably be something like  
`excluse_lines: ["OPTIONS"]`

---

<div class="post-metadata">

**Author:** ![thomas7467](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@thomas7467](https://discuss.elastic.co/u/thomas7467)\
**Post date:** [August 24, 2021, 7:52am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/3 "2021-08-24T07:52:01Z")

</div>

Hi,  
Yes, I tried this options in filebeat.yml:  
` exclude_lines: ['OPTIONS']`

It won't work I think, because the log files path comes from iis.yml module configuration files.  
the previous exclude\_lines option seems to work only for log paths files from the filebeat.yml file.

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 24, 2021, 8:34am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/4 "2021-08-24T08:34:23Z")

</div>

If I read the documentation correctly it should be possible to override these module values.

> **[IIS module | Filebeat Reference \[7.14\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-iis.html#iis-settings)**

Where did you define this `exclude_lines`?  
I think it should be under the access configuration of the module like so:

```auto
- module: iis
  access:
    enabled: true
    exclude_lines: ["^$", "OPTIONS"]
    var.paths: ["C:/inetpub/logs/LogFiles/*/*.log"]

```

(see "filebeat path"\module\iis\access\config)

---

<div class="post-metadata">

**Author:** ![thomas7467](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@thomas7467](https://discuss.elastic.co/u/thomas7467)\
**Post date:** [August 24, 2021, 9:00am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/5 "2021-08-24T09:00:05Z")

</div>

Yes I tried this in iis.yml config file that matches my config :

```auto
 access:
    enabled: true
    var.paths: [E:\LOGS\IIS\*\*\*.log]
    exclude_lines: ["OPTIONS"]

```

Unfortunately the lines are still present in elastic:

```auto
2021-08-24 08:49:31 W3SVC9 xxx xxx OPTIONS / - 8022 - 172.25.50.123 HTTP/1.0 - - - - 200 0 0 303 22 3 -

```

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 24, 2021, 9:18am UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/6 "2021-08-24T09:18:16Z")

</div>

Sorry my example was wrong. The input level was missing (see [Override input settings | Filebeat Reference [7.14] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/advanced-settings.html)).  
So the following should be in filebeat.yml:

```auto
- module: iis
  access:
    enabled: true
    input:
      exclude_lines: ["^$", "OPTIONS"]
    var.paths: ["C:/inetpub/logs/LogFiles/*/*.log"]

```

If that isn't working i have no more ideas.

---

<div class="post-metadata">

**Author:** ![thomas7467](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@thomas7467](https://discuss.elastic.co/u/thomas7467)\
**Post date:** [September 7, 2021, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/7 "2021-09-07T14:17:55Z")

</div>

Hi Christian,  
I've tried your exact syntax and it works fine 🙂 Thank you !!!

```auto
- module: iis
  # Access logs
  access:
    enabled: true
    var.paths: [E:\LOGS\IIS\*\*\*.log]
    input:
        exclude_lines: ["^$", "OPTIONS"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2021, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-how-to-exclude-lines/282306/8 "2021-10-05T16:18:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
