# Condition in metricbeat

**URL:** <https://discuss.elastic.co/t/condition-in-metricbeat/279425>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [July 22, 2021, 8:22pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425 "2021-07-22T20:22:26Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 22, 2021, 8:22pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/1 "2021-07-22T20:22:26Z")

</div>

Trying to setup condition in system.yml file for dropping some event when condition meet

what I want to do it

if this conditions meet drop the event.

( cond1 OR cond2 OR cond3 ) AND ( cond4 OR cond5 )

for example here I want to drop event

`if (user=root OR user=nagios ) AND (process.name not like "^http*" OR process.name not like "^weblogic" )`

in sort I want to drop process which start with http/weblogic and user is root or nagios

but how ever much different combination I try not working. spended hours on different kind of combination. What am I missing here?

```auto
 processors:
     - drop_event:
         when:
           or:
             equals:
               user.name: root
             equals:
               user.name: nagios
             and:
               or:
                 not:
                   regexp:
                     process.name: "^http*"
                 not:
                   regexp:
                     process.name: "^weblogic*"

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 22, 2021, 8:31pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/2 "2021-07-22T20:31:31Z")

</div>

Agree the complex logic is not easy...

EDIT Take that back your top level boolean operator according to your logic above is the `and`  
Looking at it...

More Like this

```auto
processors:
  - drop_event:
    when:
      and:
        or:
          equals:
            user.name: root
          equals:
            user.name: nagios
        or:
          not:
            regexp:
              process.name: "^http*"
          not:
            regexp:
              process.name: "^weblogic*"

```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 22, 2021, 9:09pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/3 "2021-07-22T21:09:16Z")

</div>

ok finally metricbeat started up. but still condition matching is confusing me. will try it tomorrow as it all seems more complicated at this stage. 🙂

I am just trying simple test.

I have java process running as root on system and just trying to get that and drop everything else. but in real machine I will have four more process that I need to get which runs as root

But this is not giving me that java process

`root 15326 13993 0 20:45 pts/5 00:01:54 /usr/share/logstash/jdk/bin/java -Xms1g -Xmx1g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyF`

This setting drops everything from system.

```auto
  processors:
     - drop_event:
         when:
           or:
             - equals:
                 user.name: root
             - equals:
                 user.name: sachin
             - equals:
                 user.name: kibana
             - equals:
                 user.name: elasticsearch
             - equals:
                 user.name: apm-server
             - equals:
                 user.name: rpc
             - equals:
                 user.name: dbus
           and:
             or:
               - not:
                   equals:
                      process.name: java
               - not:
                   equals:
                      process.name: sachin

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 22, 2021, 10:28pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/4 "2021-07-22T22:28:18Z")

</div>

Did You know that you can just specify the processes that you are looking for in the system module see [here](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-process.html#_configuration_11)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 23, 2021, 1:45pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/5 "2021-07-23T13:45:04Z")

</div>

Thanks Stephen but I need complicated conditions in feature

here my simple thing is not even working

For example

This works, and only gives me java process running on system.

```auto
  processors:
    - drop_event.when.or:
        - not:
            equals:
              process.name: "java"

```

As soon as I add anything to it. it stops. following does not give me any process, no output.

but in logic it says  
drop event when ( process.name != "java" OR process.name != apm-server )  
this means everything but java and apm-server correct?

```auto
  processors:
    - drop_event.when.or:
        - not:
            equals:
              process.name: "java"
        - not:
            equals:
              process.name: "apm-server"

```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 23, 2021, 2:25pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/6 "2021-07-23T14:25:43Z")

</div>

working I needed AND in place of OR

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 23, 2021, 2:44pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/7 "2021-07-23T14:44:11Z")

</div>

Good

Here is how I did it 2 Ways

You need to think highest precedence to the left

This drops everything but these 2 processes is says

Drop When  
NOT (Google OR docker)

```auto
  - drop_event.when.not.or:
    - equals.process.name: "Google Chrome H"
    - equals.process.name: "com.docker.hype"

```

Show me yours.... Yes I suspect it looks like this...

Drop When  
(NOT Google) AND (NOT docker)

```auto

  - drop_event.when.and:
    - not.equals.process.name: "Google Chrome H"
    - not.equals.process.name: "com.docker.hype"

```

Which are equivalent 🙂

BTW I like the inline short hand better ... easier for me to read.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 23, 2021, 2:52pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/8 "2021-07-23T14:52:33Z")

</div>

you right this makes more sense on reading and understanding quickly

```auto
  processors:
    - drop_event.when.and:
          - not.regexp.process.name: "java*"
          - not.regexp.process.name: "apm-server*"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2021, 4:53pm UTC](https://discuss.elastic.co/t/condition-in-metricbeat/279425/9 "2021-08-20T16:53:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
