# Regex not worked with filebeat

**URL:** <https://discuss.elastic.co/t/regex-not-worked-with-filebeat/351901>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 26, 2024, 9:00pm UTC](https://discuss.elastic.co/t/regex-not-worked-with-filebeat/351901 "2024-01-26T21:00:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ahmed\_Alsum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_alsum/32/131146_2.png) [@Ahmed\_Alsum](https://discuss.elastic.co/u/Ahmed_Alsum)\
**Post date:** [January 26, 2024, 9:00pm UTC](https://discuss.elastic.co/t/regex-not-worked-with-filebeat/351901/1 "2024-01-26T21:00:03Z")

</div>

Hi Dear,  
I'm trying to exclude any files starting with **gc** but below regex did not work  
and regex is verified, myfilebeat version is :8.3.2

```auto
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

# filestream is an input for collecting log messages from files.
- type: filestream

  # Unique ID among all inputs, an ID is required.
  id: my-filestream-id

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    #- c:\programdata\elasticsearch\logs\*
    - /app/softwareag/wm1011/IntegrationServer/instances/default/*

  ignore_older: 24h
  close_inactive: 5m
  clean_inactive: 30h

  prospector.scanner.exclude_files: ['.gz$', '^gc.*']

```

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 26, 2024, 9:21pm UTC](https://discuss.elastic.co/t/regex-not-worked-with-filebeat/351901/2 "2024-01-26T21:21:14Z")

</div>

> [@Ahmed\_Alsum](#):
>
> `prospector.scanner.exclude_files`

I believe exclude files is not applied to the filename but instead to the path so I _think_ you would need a regex that matches `/app/softwareag/wm1011/IntegrationServer/instances/default/gc.........` which yours won't because of the start of line anchor `^`

---

<div class="post-metadata">

**Author:** ![Ahmed\_Alsum](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_alsum/32/131146_2.png) [@Ahmed\_Alsum](https://discuss.elastic.co/u/Ahmed_Alsum)\
**Post date:** [January 26, 2024, 10:02pm UTC](https://discuss.elastic.co/t/regex-not-worked-with-filebeat/351901/3 "2024-01-26T22:02:58Z")

</div>

thanks worked after changed to full path

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2024, 12:03am UTC](https://discuss.elastic.co/t/regex-not-worked-with-filebeat/351901/4 "2024-02-24T00:03:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
