# Are processors applied to the filebeat application logs?

**URL:** <https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 23, 2024, 7:57am UTC](https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598 "2024-01-23T07:57:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dragan\_Bosnjak](https://avatars.discourse-cdn.com/v4/letter/d/cc9497/32.png) [@Dragan\_Bosnjak](https://discuss.elastic.co/u/Dragan_Bosnjak)\
**Post date:** [January 23, 2024, 7:57am UTC](https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598/1 "2024-01-23T07:57:11Z")

</div>

I am trying to filter out some filebeat logs with `drop_event` processor, but it doesn't seem to work. This is the event:

```auto
{
"log.level":"warn",
"@timestamp":"2024-01-01T12:11:22.333Z",
"log.logger":"file_watcher",
"log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*fileWatcher).watch","file.name":"filestream/fswatch.go","file.line":205},
"message":"file \"/var/log/example.log\" has no content yet, skipping",
"service.name":"filebeat",
"ecs.version":"1.6.0"}

```

and i'm trying to drop it like this:

```yaml
processors:
 - drop_event:
     when:
       equals:
         service.name: "filebeat"

```

Is my configuration syntax incorrect? Are processors even appliend to internal logs?

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 23, 2024, 8:30am UTC](https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598/2 "2024-01-23T08:30:03Z")

</div>

> [@Dragan\_Bosnjak](#):
>
> `"message":"file \"/var/log/example.log\" has no content yet, skipping",`

Hi,

processors might not be applied to internal logs. If you want to reduce the verbosity of Filebeat's internal logging, you can adjust the logging level in the Filebeat configuration. For example, you can set `logging.level: error` to only log error messages.

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2024, 10:30am UTC](https://discuss.elastic.co/t/are-processors-applied-to-the-filebeat-application-logs/351598/3 "2024-02-20T10:30:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
