# Drop\_event filter

**URL:** https://discuss.elastic.co/t/drop-event-filter/356638
**Category:** Beats
**Tags:** metricbeat
**Created:** [April 2, 2024, 8:42pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638 "2024-04-02T20:42:50Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 2, 2024, 8:42pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/1 "2024-04-02T20:42:50Z")

</div>

I have following filter in system.yml file and working fine

dropping event if username is root or ntp or process has myjob.\* pattern.

```auto
  processors:
     - drop_event:
         when:
           or:
           - equals:
               user.name: root
           - equals:
               user.name: ntp
           - regexp:
               process.name: "myjob.*"

```

I want to add one more condition

drop event  
if user = root or ntp or regexp (process.name = myjob.\* and not drop if regexp(process.name = sachin.\*

I try following but not working. what am I missing?

```auto
  processors:
     - drop_event:
         when:
           or:
           - equals:
               user.name: root
           - equals:
               user.name: ntp
           - regexp:
               process.name: "myjob.*"
           not:
           - regexp:
              process.name: "sachin.*"

```

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 3, 2024, 1:48pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/2 "2024-04-03T13:48:58Z")

</div>

I just used this but not getting anything

```auto
  processors:
     - drop_event:
         when:
           not:
             equal:
               process_fullname: "sachin-dev.service.31746"

```

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 3, 2024, 3:17pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/3 "2024-04-03T15:17:15Z")

</div>

I remove all the processor and make sure I have that event. and yes I do

then use different condition. like  
process.name =

but seems like I am not placing NOT at correct place

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 3, 2024, 6:00pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/4 "2024-04-03T18:00:08Z")

</div>

please help if anyone has ever use this kind of expression.

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 3, 2024, 7:19pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/5 "2024-04-03T19:19:55Z")

</div>

further more testing debugging still not getting what I want

two individual processors works

1. drops all event which has user.name = root

```auto
  processors:
     - drop_event:
         when:
           or:
           - equals:
               user.name: root

```

1. drop all event which has no process.name=sachin-gateway

```auto
  processors:
     - drop_event:
         when:
           not:
             equals:
               process.name: sachin-gateway

```

how do I combine them so all process with user.name=root drop except process.name=sachin-gateway

I try many different method none works.

this one drops all process with user.name=root

```auto
  processors:
     - drop_event:
         when:
           and:
             equals.user.name: root
             not.equals.process.name: sachin-gateway.pr

```

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 3, 2024, 7:56pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/6 "2024-04-03T19:56:06Z")

</div>

alright this works

```auto

  processors:
    - drop_event.when.and:
        - equals.user.name: root
        - not.equals.process.name: sachin-gateway

```

but I want to add or condition with this to drop

user.name = zabbix or user.name = postfix or user.name=statd etc...

basically something like this

drop\_event when:  
( username=root and NOT process.name=sachin.gateway) or (username=nscd or username=postfix or username=xyz)

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [April 4, 2024, 3:22pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/7 "2024-04-04T15:22:16Z")

</div>

Alright fixed it.

just incase if someone had same issue

```auto
  processors:
    - drop_event.when:
        and:
          - equals.user.name: root
          - not.equals.process.name: sachin-gateway
    - drop_event.when:
        or:
          - equals.user.name: postfix
          - equals.user.name: zabbix

```

In place of combining two condition wrote it out seperatly.

drop\_event when  
(user.name=root AND NOT process.name=sachin-gateway)  
drop\_event when  
(user.name=postfix OR user.name=zabbix)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 2, 2024, 5:23pm UTC](https://discuss.elastic.co/t/drop-event-filter/356638/8 "2024-05-02T17:23:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
