# Unable to sync only documents that match connector include rules

**URL:** <https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418>\
**Category:** Kibana\
**Tags:** connectors\
**Created:** [February 12, 2025, 10:15am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418 "2025-02-12T10:15:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![anielo](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@anielo](https://discuss.elastic.co/u/anielo)\
**Post date:** [February 12, 2025, 10:15am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418/1 "2025-02-12T10:15:02Z")

</div>

Hi there,

I am setting up a MySQL connector to synchronise a table with Elasticsearch. My use case is to synchronise only rows that have a field matching a given value (and exclude all the others).

I created one include rule as follows (rule with prio 0):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/e/deca92ca78e8b029675747dce0b332dba49d4aa6.png)

The rule with prio 1 is a default and uneditable rule that includes everything else (a default also described in the documentation). As expected, my rule is useless since the default rule includes everything.

But how do I **only** include the rows with the `post_type` field set to `product`?

I tried to create a catch-all exclusion rule similar to the default inclusion rule. Validation fails however:

```auto
Sync rule 0a555db2-9cbd-4ed7-939a-8336def57d20 is invalid.

Basic rule 2 (id: '0a555...57d20') is semantically equal to Basic rule 3 (id: 'D...T').

Basic rule 2 (id: '0a555...57d20') uses a match all regexps ['.*', '(.*)'], which are not allowed.

```

The error saying that the rule is semantically equivalent to the default rule is wrong as it excludes everything else (and not includes).

How do I implement my use case? I also tried implementing this with the [filtering API](https://www.elastic.co/docs/api/doc/elasticsearch/v8/operation/operation-connector-update-filtering) with no luck.

Since it is not possible to define a "not equal" rule and since the default catch-all rule cannot be changed, I do not see how to implement this. Inclusion rules do not seem very useful if this is the default anyway.

Is there a way to change this default rule to an exclude rule?

Thanks for your help,  
Angelo

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [February 18, 2025, 9:48pm UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418/2 "2025-02-18T21:48:29Z")

</div>

We probably need to re-evaluate if match-all rules should be allowed, if there's a preceeding rule.

As a temporary workaround, you could use a regex rule to match anything except `product`, and use "Exclude" for that rule.

Alternatively, you can add explicit "Exclude" rules for all other types of `post_type` values.

---

<div class="post-metadata">

**Author:** ![Vaibhav\_Udaywal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vaibhav_udaywal/32/144384_2.png) [@Vaibhav\_Udaywal](https://discuss.elastic.co/u/Vaibhav_Udaywal)\
**Post date:** [July 30, 2025, 6:15am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418/3 "2025-07-30T06:15:14Z")

</div>

Facing the same, have we re-evaluate?

Temporary workaround won't be a scalable solution if we need to add multiple rules.

---

<div class="post-metadata">

**Author:** ![Vaibhav\_Udaywal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vaibhav_udaywal/32/144384_2.png) [@Vaibhav\_Udaywal](https://discuss.elastic.co/u/Vaibhav_Udaywal)\
**Post date:** [July 30, 2025, 6:17am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418/4 "2025-07-30T06:17:39Z")

</div>

how does the inclusion works under basic sync rule engine?  
There’s always a default rule suggests everything else included.

```auto
{
    field: '_',
    id: 'DEFAULT',
    order: rules.length,
    policy: 'include',
    rule: 'regex',
    value: '.*',
}

```

So If I select a shared\_drive in inclusion, it still syncs all data, not just that shared drive.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/016f6ea87cd0dbb6393e35e3bd1b4bb0acc5dba4.png)

And if i try to play around the default policy, it never allow us to modify, adding additional policy returns the following error.

```auto
{
  "ids": [
      "DEFAULT"
  ],
  "messages": [
      "Basic rule 4 (id: 'D...T') is semantically equal to Basic rule 3 (id: '4be03...9f58d')."
  ]
},
{
  "ids": [
      "4be0393e-0beb-4f6b-8d47-bdbcfe09f58d"
  ],
  "messages": [
      "Basic rule 3 (id: '4be03...9f58d') is semantically equal to Basic rule 4 (id: 'D...T')."
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Vaibhav\_Udaywal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vaibhav_udaywal/32/144384_2.png) [@Vaibhav\_Udaywal](https://discuss.elastic.co/u/Vaibhav_Udaywal)\
**Post date:** [August 1, 2025, 4:38am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418/5 "2025-08-01T04:38:37Z")

</div>

Made a slight change in second last case to exclude everything. It's workaround but worked.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da654bf258b51afb4c6728acc0ef5862c6825906.png)

---

<div class="post-metadata">

**Author:** ![Artem\_Shelkovnikov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artem_shelkovnikov/32/134322_2.png) [@Artem\_Shelkovnikov](https://discuss.elastic.co/u/Artem_Shelkovnikov)\
**Post date:** [August 1, 2025, 9:37am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418/6 "2025-08-01T09:37:26Z")

</div>

You can also just change it to `.+` or `.*.*` to make it work.
