# Yet another exclude\_lines thread

**URL:** <https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239>\
**Category:** Beats\
**Created:** [January 23, 2020, 12:30pm UTC](https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239 "2020-01-23T12:30:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kwisatz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kwisatz/32/61277_2.png) [@kwisatz](https://discuss.elastic.co/u/kwisatz)\
**Post date:** [January 23, 2020, 12:30pm UTC](https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239/1 "2020-01-23T12:30:59Z")

</div>

I'm sorry to have to open yet another `exclude_lines` thread, but having read all the available threads and checked all possibilities, I still can't get the `exclude_lines` option to work.

My config is:

```auto
filebeat:
  prospectors:
  - document_type: log
    exclude_lines:
    - .*ping.*
    fields:
      gl2_source_collector: bd4ffc76-23b4-49c1-87df- ******
    ignore_older: 0
    input_type: log
    paths:
    - /var/log/nginx/*.log
    scan_frequency: 10s
    tail_files: true
output:
  logstash:
    hosts:
    - ***** :5044
path:
  data: /var/cache/graylog/collector-sidecar/filebeat/data
  logs: /var/log/graylog/collector-sidecar
tags:
- linux
- nginx
- phpfpm

```

I don't think that I'm using any type of module for which I'd have to override any settings, and yet, log lines like these are still getting shipped:

```auto
192.168.8.10 - - [21/Jan/2020:10:01:24 +0100] "GET /ping HTTP/1.0" 200 15

```

I've tried a variety of regular expressions and this one is the simplest that should match this line (and perhaps others but I don't care at the moment).

Any ideas what else I could check?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 23, 2020, 3:54pm UTC](https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239/2 "2020-01-23T15:54:16Z")

</div>

Hi @kwisatz,

Just in case it is being misinterpreted, could you try to quote the pattern in `exclude_lines`?

```auto
filebeat:
  prospectors:
  - document_type: log
    exclude_lines:
    - '.*ping.*'
...

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2020, 5:54pm UTC](https://discuss.elastic.co/t/yet-another-exclude-lines-thread/216239/3 "2020-02-20T17:54:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
