# Kibana automatic activity is flooding audit log

**URL:** <https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413>\
**Category:** Kibana\
**Created:** [March 21, 2017, 12:40pm UTC](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413 "2017-03-21T12:40:04Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Guy\_Shilo](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@Guy\_Shilo](https://discuss.elastic.co/u/Guy_Shilo)\
**Post date:** [March 27, 2017, 10:35am UTC](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413/10 "2017-03-27T10:35:19Z")

</div>

Hello

I am not that great with regular expressions, however, trying to filter out Kibana monitoring messages, I came up with this regexp:  
principal=.Kibana.|.indices=..(monitoring-data-2|kibana)..|action=.\*cluster:monitor\*

I tested it with an [online Java regexp tester](http://www.freeformatter.com/java-regex-tester.html) and it was good and matched all the required messages. But when I inserted it to log4j2.properties and restarted, it seems like Elasticsearch is completely ignoring it !

I keep seeing the messages in the audit file...

Any ideas ?

Thanks

Guy

---

_[View the full topic](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413)._
