# Drop all system event

**URL:** <https://discuss.elastic.co/t/drop-all-system-event/252366>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [October 16, 2020, 3:45pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366 "2020-10-16T15:45:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [October 16, 2020, 3:45pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/1 "2020-10-16T15:45:40Z")

</div>

I just want to monitor user processed using metricbeat

currently it is giving me all the system process as well like kworker, systemd etc...

how do I drop them? I think drop\_event in system.yml file needs to be set. but I do not understand it correctly.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [October 16, 2020, 6:04pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/2 "2020-10-16T18:04:38Z")

</div>

Have you tried using the `processes` setting of the `system/process` metricset? [https://www.elastic.co/guide/en/beats/metricbeat/6.8/metricbeat-metricset-system-process.html#\_configuration\_10](https://www.elastic.co/guide/en/beats/metricbeat/6.8/metricbeat-metricset-system-process.html#_configuration_10)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [October 16, 2020, 6:20pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/3 "2020-10-16T18:20:37Z")

</div>

there is no exclude event or drop event on that document page

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [October 16, 2020, 6:22pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/4 "2020-10-16T18:22:31Z")

</div>

Right, I was thinking you could use the `processes` setting to define the list of user processes you are interested in monitoring, unless you want to monitor _all_ user processes?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [October 16, 2020, 6:25pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/5 "2020-10-16T18:25:17Z")

</div>

No I want to do it other way around. I want to grab everything from system which is not user = root

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [October 16, 2020, 6:38pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/6 "2020-10-16T18:38:09Z")

</div>

Got it, thanks.

If you look at the event produced by the `system/process` metricset (example event is shown on [https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-process.html](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-process.html)), you'll see that there's a `user.name` field in the event. You can then use the `drop_event` processor to drop events with `user.name` equal to `root`: [https://www.elastic.co/guide/en/beats/metricbeat/current/drop-event.html](https://www.elastic.co/guide/en/beats/metricbeat/current/drop-event.html).

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [October 16, 2020, 7:53pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/7 "2020-10-16T19:53:21Z")

</div>

Perfect. worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2020, 9:53pm UTC](https://discuss.elastic.co/t/drop-all-system-event/252366/8 "2020-11-13T21:53:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
