# Regex matching expression to exclude line

**URL:** <https://discuss.elastic.co/t/regex-matching-expression-to-exclude-line/157527>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 20, 2018, 11:34am UTC](https://discuss.elastic.co/t/regex-matching-expression-to-exclude-line/157527 "2018-11-20T11:34:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Miguel\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_leite/32/41988_2.png) [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Post date:** [November 20, 2018, 11:34am UTC](https://discuss.elastic.co/t/regex-matching-expression-to-exclude-line/157527/1 "2018-11-20T11:34:50Z")

</div>

Hey!

I want to exclude a line with filebeat, that is the following:

`(ERROR) Can't find TpTag 'TagUid' in TpPin`

Anyone knows how to match that full line with regular expressions? Those apostrophes aren't letting me start filebeat...

---

<div class="post-metadata">

**Author:** ![kgl](https://avatars.discourse-cdn.com/v4/letter/k/4da419/32.png) [@kgl](https://discuss.elastic.co/u/kgl)\
**Post date:** [November 20, 2018, 1:16pm UTC](https://discuss.elastic.co/t/regex-matching-expression-to-exclude-line/157527/2 "2018-11-20T13:16:14Z")

</div>

The following worked for me on filebeat 6.0.0

## Input file - bla.log

```
(ERROR) Can't find TpTag 'TagUid' in TpPin
(INFO) Can't find TpTag 'TagUid' in TpPin
(INFO) The quick brown fox jumps over the lazy dog
This one will be rightfully ignored (ERROR) Can't find TpTag 'TagUid' in TpPin

```

## filebeat config

```
filebeat.prospectors:
- type: log
  exclude_lines: [^\(ERROR\) Can\'t find TpTag \'TagUid\' in TpPin$]
  paths:
   - "C:/dev/elk_test_env/test/bla.log"
output.logstash:
  hosts: ["localhost:5080"]

```

 ![test](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9ad56b86c97362b7fdaa556979ef59303dd9444e.png)

As mentioned in [Regular expression support | Beats](https://www.elastic.co/guide/en/beats/filebeat/current/regexp-support.html)

> [@](#):
>
> We recommend that you wrap regular expressions in single quotation marks to work around YAML’s string escaping rules. For example, `'^\[?[0-9][0-9]:?[0-9][0-9]|^[[:graph:]]+'` .

The single quotation marks are **recommended** but **not** necessary.

---

<div class="post-metadata">

**Author:** ![Miguel\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_leite/32/41988_2.png) [@Miguel\_Leite](https://discuss.elastic.co/u/Miguel_Leite)\
**Post date:** [November 20, 2018, 2:03pm UTC](https://discuss.elastic.co/t/regex-matching-expression-to-exclude-line/157527/3 "2018-11-20T14:03:40Z")

</div>

Yeah, thanks, it also worked for me... I really didn't need the single quotes on the exclude line configuration!  
The one thing I didn't try... Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2018, 2:03pm UTC](https://discuss.elastic.co/t/regex-matching-expression-to-exclude-line/157527/4 "2018-12-18T14:03:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
