# How to filter in filebeat yml file

**URL:** <https://discuss.elastic.co/t/how-to-filter-in-filebeat-yml-file/284978>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 23, 2021, 9:25am UTC](https://discuss.elastic.co/t/how-to-filter-in-filebeat-yml-file/284978 "2021-09-23T09:25:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bae\_park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bae_park/32/81552_2.png) [@bae\_park](https://discuss.elastic.co/u/bae_park)\
**Post date:** [September 23, 2021, 9:25am UTC](https://discuss.elastic.co/t/how-to-filter-in-filebeat-yml-file/284978/1 "2021-09-23T09:25:07Z")

</div>

While using kafka input, I want to output only when json data contains a specific string.

I tried setting "include\_lines" in filebeat.yml, but it was not filtered properly.

When the filebit.yml setting is as follows and data-set1 and 2 are input, not only data-set1 but also data-set2 are output.

I expected only data-set 1 to be output, but it wasn't.

What did I make a mistake?

- part of the filebeat.yml

```auto
filebeat.inputs:
- type: kafka
  hosts:
    - qa-parkbae-01.hanpda.com:9092,
    - qa-parkbae-02.hanpda.com:9092,
    - qa-parkbae-03.hanpda.com:9092
  topics: ["parkbae-test-topic1"]
  group_id: "test123"
  ssl.enabled: false

  include_lines: ['\"event\":\"basket\"']

```

- data-set1  
{"id":"parkbae","event":"basket","data":"test1"}

- data-set2  
{"id":"parkbae","event":"ball","data":"test2"}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2021, 11:26am UTC](https://discuss.elastic.co/t/how-to-filter-in-filebeat-yml-file/284978/2 "2021-10-21T11:26:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
