# Log4j regex filter to avoid audit logs

**URL:** <https://discuss.elastic.co/t/log4j-regex-filter-to-avoid-audit-logs/226016>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 1, 2020, 9:47am UTC](https://discuss.elastic.co/t/log4j-regex-filter-to-avoid-audit-logs/226016 "2020-04-01T09:47:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Javier\_Parrondo](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@Javier\_Parrondo](https://discuss.elastic.co/u/Javier_Parrondo)\
**Post date:** [April 1, 2020, 9:47am UTC](https://discuss.elastic.co/t/log4j-regex-filter-to-avoid-audit-logs/226016/1 "2020-04-01T09:47:44Z")

</div>

Hello,

I would like to avoid messages like the followings inside my {cluster\_name}\_audit.log:

{"@timestamp":"2020-04-01T10:11:54,869", "xxxxxxxxxxxxxxxxxxx"user.name":"kibana", "user.realm":"reserved", "user.roles":["kibana\_system"], xxxxxxxxxxxxxxxx}  
{"@timestamp":"2020-04-01T10:11:54,869", "xxxxxxxxxxxxxxxxxxx"user.name":"nagios", "user.realm":"reserved", "user.roles":["nagios\_role"], xxxxxxxxxxxxxxxx}  
{"@timestamp":"2020-04-01T10:11:54,869", "xxxxxxxxxxxxxxxxxxx"user.name":"elastic", "user.realm":"reserved", "user.roles":["superuser"], xxxxxxxxxxxxxxxx}

Do you know what i have to set inside the log4j.properties to avoid this kind of messages? I have tried with a sum of regex expressions but it is not work for me, the only regex filter that works is the following:

`appender.audit_rolling.filter.regex.regex = .*kibana\".*|.*\"nagios\".*|.*\"elastic\".*`

but I would like to be more accurate and capture something like this:

`appender.audit_rolling.filter.regex.regex = .*user.name\":\"kibana.*|.*user.name\":\"nagios.*|.*user.name\":\"elastic.*`  
I have test with some regex filter calculator and this works but in elasticsearch does not.

Could you help me? The version of my elasticsearch cluster is 6.8.4

Thanks for all.  
Best Regards

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 1, 2020, 2:44pm UTC](https://discuss.elastic.co/t/log4j-regex-filter-to-avoid-audit-logs/226016/2 "2020-04-01T14:44:53Z")

</div>

Hi there Javier, what you need is [audit log exclude policies](https://www.elastic.co/guide/en/elasticsearch/reference/current/audit-log-output.html#audit-log-ignore-policy) i.e. something like

```auto
xpack.security.audit.logfile.events.ignore_filters:
  example1:
    users: ["kibana", "nagios", "elastic"]

```

---

<div class="post-metadata">

**Author:** ![Javier\_Parrondo](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@Javier\_Parrondo](https://discuss.elastic.co/u/Javier_Parrondo)\
**Post date:** [April 1, 2020, 3:32pm UTC](https://discuss.elastic.co/t/log4j-regex-filter-to-avoid-audit-logs/226016/3 "2020-04-01T15:32:08Z")

</div>

Hello Ikakavas,

Yes I know this configuration inside the elasticsearch.yml and via API (cluster settings API) but I would like to know if the regex filters are been deprecated or removed in version 6.x because in version 5.6 it works fine!!!

Do you know if there have been any changes regarding this topic?

Thanks for all.  
Best Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 3:32pm UTC](https://discuss.elastic.co/t/log4j-regex-filter-to-avoid-audit-logs/226016/4 "2020-04-29T15:32:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
