# Include\_lines problem

**URL:** <https://discuss.elastic.co/t/include-lines-problem/52723>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 14, 2016, 10:52am UTC](https://discuss.elastic.co/t/include-lines-problem/52723 "2016-06-14T10:52:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [June 14, 2016, 10:52am UTC](https://discuss.elastic.co/t/include-lines-problem/52723/1 "2016-06-14T10:52:44Z")

</div>

Hi,  
I am trying to configure Filebeats to only process lines from my logs which match a couple of regexes. Nothing too complicated.

I set it up like this:

`include_lines: [".*returned\sthe\sstatus.*",".*information\sfrom\sthe\sgreen\sServer.*"]`

But then I cannot start the Filebeat service.

It does however work with:-  
`include_lines: [".*returned the status.*",".*information from the green Server.*"]`

However, for some strange reason lots and lots of other lines are also being caught and sent into ES.

My questions are:-

1. Why is filebeats borking at the \s in the regex??
2. What regex implementation does Filebeats actually use?

Thanks.

UPDATE  
Bit more testing. I simplified the include\_lines to be a single expression:-  
`include_lines: ["returned the status"]`

But I am getting all manner of lines sent into ES. Not just the lines one might expect.  
This is on a Windows machine. Can anyone shed any light on why "inlclude\_line" is just doing its own thing?

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [June 14, 2016, 3:54pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/2 "2016-06-14T15:54:37Z")

</div>

Hi,

I have now tried many combinations of regex using:

include\_lines and exclude\_lines

There appears to be no way to only collect the lines that I want. Every combination I have tried thus far has resulted in completely unexpected lines also being shipped to elasticsearch.

As far as I can tell include\_lines and exclude\_lines simply do not work. I have reduced this problem down to a very simple scenario where all I want to send to Elasticsearch are lines matching a very simple pattern. No matter what I do, everything is sent.

Can anyone please chime in here and advise if this is a known issue on Windows? PLEASE?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 14, 2016, 5:49pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/3 "2016-06-14T17:49:06Z")

</div>

What version of Filebeat are you using?

> [@Kryten](#):
>
> I have reduced this problem down to a very simple scenario...

Can you share the config file and sample log file for this scenario? This will help someone reproduce the problem and determine if it is a bug.

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [June 14, 2016, 5:52pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/4 "2016-06-14T17:52:24Z")

</div>

Hi,

I have tried with 1.2.3 and the latest v5 alpha currently offered as a download (5.0.0-alpha3-windows).

I can share both the config file and an excerpt from the log file, but it will have to be privately. Would you like me to DM you with more details?

Thanks

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [June 14, 2016, 6:06pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/5 "2016-06-14T18:06:05Z")

</div>

Thank you @andrewkroh the information has been sent by DM.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 14, 2016, 6:30pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/6 "2016-06-14T18:30:41Z")

</div>

The indentation for the `encoding` and `include_lines` options is wrong. They need to be moved 4 spaces to right because they are options associated with the prospector. See the indentation is the default config file: [https://github.com/elastic/beats/blob/1.2/filebeat/etc/filebeat.yml#L41](https://github.com/elastic/beats/blob/1.2/filebeat/etc/filebeat.yml#L41)

Also `include_lines` expects a list of strings and not a single string. So enclose the value in `["value"]` in brackets.

The encoding you specified for the log file does not match the sample log file you sent. There is no BOM in that file so just remove the encoding setting from your config file.

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [June 14, 2016, 6:45pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/7 "2016-06-14T18:45:58Z")

</div>

Thanks Andrew, I will try that first thing tomorrow.

I had tried the brackets around the strings and understand that. The issue is most likely the indentation.

Appreciate it.

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [June 14, 2016, 7:34pm UTC](https://discuss.elastic.co/t/include-lines-problem/52723/8 "2016-06-14T19:34:53Z")

</div>

Yes, that was it. Now getting what I need. Thank you so much.

Now that it is only processing the lines I need, however, the filebeats.exe is taking 70% CPU on the host machine. Will need to look into that in the morning.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2016, 10:53am UTC](https://discuss.elastic.co/t/include-lines-problem/52723/9 "2016-07-05T10:53:53Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
