# How can I match on all log files except ones containing a string

**URL:** <https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 11, 2021, 8:59pm UTC](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415 "2021-10-11T20:59:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dsdameron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsdameron/32/62387_2.png) [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Post date:** [October 11, 2021, 8:59pm UTC](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415/1 "2021-10-11T20:59:35Z")

</div>

We are ingesting the our CPanel system's Apache logs with Filebeat's handy [apache module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache.html#_access_log_fileset_settings). Our configuration is as follows:

```auto
   var.paths:
      - "/var/log/apache2/domlogs/*"

```

However, I've hit a snag. I need to grab all files in this directory except logs containing -bytes. For example, one site would have the following logs in /var/log/apache2/domlogs/:

```auto
something.example.com
something.example.com-bytes_log
something.example.com-ssl_log

```

How can I tell filebeat to pickup [something.example.com](http://something.example.com), something.example.com-ssl\_log, but not something.example.com-bytes\_log? I'm sure there is a way, but I don't see how to say match unless the file contains "-bytes"

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [October 12, 2021, 11:41pm UTC](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415/2 "2021-10-12T23:41:45Z")

</div>

Are those different lines or the names of different files? If files, just modify the glob. If lines u can use the `exclude_lines` config.

---

<div class="post-metadata">

**Author:** ![dsdameron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsdameron/32/62387_2.png) [@dsdameron](https://discuss.elastic.co/u/dsdameron)\
**Post date:** [October 18, 2021, 1:20pm UTC](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415/3 "2021-10-18T13:20:35Z")

</div>

Thank for the reply @legoguy1000. Those are the names of different files. I was trying to make my expression match all files within /var/log/apache2/domlogs/\*, but exclude files containing -bytes\_log. I ended up taking the lazy route and dropping the event if the filename contains "-bytes\_log"

```auto
- module: apache
  # Access logs
  access:

    enabled: true

    input:
      processors:
        - drop_event:
            when.contains:
              log.file.path: "-bytes_log"

```

It would have been nice to make the expression do an exclusion, but I couldn't get that working...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2021, 3:20pm UTC](https://discuss.elastic.co/t/how-can-i-match-on-all-log-files-except-ones-containing-a-string/286415/4 "2021-11-15T15:20:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
