# Block certain strings from ingestion

**URL:** <https://discuss.elastic.co/t/block-certain-strings-from-ingestion/322326>\
**Category:** Elasticsearch\
**Created:** [January 2, 2023, 3:46pm UTC](https://discuss.elastic.co/t/block-certain-strings-from-ingestion/322326 "2023-01-02T15:46:40Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 2, 2023, 6:11pm UTC](https://discuss.elastic.co/t/block-certain-strings-from-ingestion/322326/2 "2023-01-02T18:11:02Z")

</div>

Hi @rahul_sirugudi

Perhaps look at filebeat [drop event processor](https://www.elastic.co/guide/en/beats/filebeat/current/drop-event.html)

Or perhaps look at one of the many logstash topics on this...

> [@Drop the complete message containing specific strings](https://discuss.elastic.co/t/drop-the-complete-message-containing-specific-strings/197799/1):
>
> Hello, I have the following definition to drop messages from a log file containing strings and text: input { file { path =\> "/opt/mapr/logs/cldb.log" tags =\> "mapr\_cldb" codec =\> plain {charset =\> "ISO-8859-1"} } } filter { if "INFO" in [message] { drop{ } } if "[CLDB-1]:" in [message] { drop{ } } if "reqIncoming" in [message] { drop{ } } if "The server has decided to close" in [message] { drop{ } } if "WARN log" in [message] { drop{ } } if "RpcProgram not found" in [message] { dr…

---

_[View the full topic](https://discuss.elastic.co/t/block-certain-strings-from-ingestion/322326)._
