# Drop entire log if condition is met

**URL:** <https://discuss.elastic.co/t/drop-entire-log-if-condition-is-met/38604>\
**Category:** Logstash\
**Created:** [January 7, 2016, 11:26am UTC](https://discuss.elastic.co/t/drop-entire-log-if-condition-is-met/38604 "2016-01-07T11:26:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lethalMango](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@lethalMango](https://discuss.elastic.co/u/lethalMango)\
**Post date:** [January 7, 2016, 11:26am UTC](https://discuss.elastic.co/t/drop-entire-log-if-condition-is-met/38604/1 "2016-01-07T11:26:12Z")

</div>

Forgive me if I've missed this in the docs as I couldn't see it.

Is it possible to drop an entire log based on a condition?

i.e. eventlog\_id 5156 is never needed and is disabled on the majority of servers we have. Rather than output these to elasticsearch can any WindowsEventLog types with the eventlog\_id field = 5156 just be ignored rather than outputting to elasticsearch?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 7, 2016, 12:13pm UTC](https://discuss.elastic.co/t/drop-entire-log-if-condition-is-met/38604/2 "2016-01-07T12:13:51Z")

</div>

By "drop an entire log" I assume you mean drop the current event. Yes, that's easy:

```auto
filter {
  if [eventlog_id] == 5156 {
    drop { }
  }
}

```

This assumes that `eventlog_id` is an integer field. If it's a string field (which it probably shouldn't be) you'll have to double quote the value (i.e. use `"5156"` instead).

---

<div class="post-metadata">

**Author:** ![lethalMango](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@lethalMango](https://discuss.elastic.co/u/lethalMango)\
**Post date:** [January 7, 2016, 1:43pm UTC](https://discuss.elastic.co/t/drop-entire-log-if-condition-is-met/38604/3 "2016-01-07T13:43:51Z")

</div>

> [@magnusbaeck](#):
>
> By "drop an entire log" I assume you mean drop the current event.

I believe so. I'm basically looking to prevent any logs with `eventlog_id` equalling 5156 from being passed to the output and therefore never being indexed by Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:16am UTC](https://discuss.elastic.co/t/drop-entire-log-if-condition-is-met/38604/4 "2017-07-06T05:16:31Z")

</div>


