# "Drop\_event" does not work

**URL:** <https://discuss.elastic.co/t/drop-event-does-not-work/105755>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [October 30, 2017, 11:33am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755 "2017-10-30T11:33:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AmosChen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amoschen/32/24676_2.png) [@AmosChen](https://discuss.elastic.co/u/AmosChen)\
**Post date:** [October 30, 2017, 11:33am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755/1 "2017-10-30T11:33:02Z")

</div>

Hello  
I have a filter in my metricbeat.yml,part of the config file like this:

```
- module: system
  metricsets: [network]
  enabled: true
  filters:
    - drop_event.when.equals.system.network.name: lo

```

I want to drop the event named "lo" ,but it does not work .I can get the data from "lo" device via kibana and contines to grow.

Can you help me please  
best regards.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 30, 2017, 12:07pm UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755/2 "2017-10-30T12:07:01Z")

</div>

Hi @AmosChen,

What version of Metricbeat are you using? Try changing `filters` to `processors`

---

<div class="post-metadata">

**Author:** ![AmosChen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amoschen/32/24676_2.png) [@AmosChen](https://discuss.elastic.co/u/AmosChen)\
**Post date:** [October 31, 2017, 3:17am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755/3 "2017-10-31T03:17:10Z")

</div>

Thank you so much for your reply.  
The version of Metricbeat is 5.6.2.  
According to your suggestion，the filters was changed by processors,but it is still useless，anticipates your reply。

best regards.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 31, 2017, 10:25am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755/4 "2017-10-31T10:25:05Z")

</div>

Could you please paste the resulting config? This is something we ship by default and so far it works:

> <https://github.com/elastic/beats/blob/master/metricbeat/modules.d/system.yml#L25>

---

<div class="post-metadata">

**Author:** ![AmosChen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amoschen/32/24676_2.png) [@AmosChen](https://discuss.elastic.co/u/AmosChen)\
**Post date:** [November 1, 2017, 2:20am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755/5 "2017-11-01T02:20:00Z")

</div>

Hi @exekias  
I have solved this problem using your tips .The reference documentation: The filter setting in metricbeat 5.x is applied on the non-finalized event. You have to access the keys by it’s local name. For example the mount\_point its full name is system.filesystem.mount\_point. The local name of [system.network.name](http://system.network.name) is just name. so I replace '[system.network.name](http://system.network.name)' with 'name', the filter does [work.It](http://work.It) seems like that

- module: system  
metricsets: [network]  
enabled: true  
filters:
  - drop\_event:  
when:  
- equals:  
name: lo

thanks.😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 2:33am UTC](https://discuss.elastic.co/t/drop-event-does-not-work/105755/6 "2017-11-29T02:33:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
