Drop _event when regexp dropping every event - apache2 module

Hi everyone,

I wanted to limit the number of documents stored in Elasticsearch. So I configured a processor in my filebeat.yml at the top-level. My input is the apache2 module which is configured fine.

    - drop_event:
               apache2.access.url: '\/(tag|track)\?'

I want to drop events where the url looks like this

  • /tag?something=value...
  • /track?something=value...

Here is a sample input: - - [16/Nov/2018:13:56:17 +0000] "GET /tag?something=value HTTP/1.1" 200 724 "[referer]"[user-agent]"

Can someone point me to what exactly I'm doing wrong?
Thank you.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.