# Drop \_event when regexp dropping every event - apache2 module

**URL:** <https://discuss.elastic.co/t/drop-event-when-regexp-dropping-every-event-apache2-module/157084>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 16, 2018, 2:43pm UTC](https://discuss.elastic.co/t/drop-event-when-regexp-dropping-every-event-apache2-module/157084 "2018-11-16T14:43:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alaa\_Ksontini](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@Alaa\_Ksontini](https://discuss.elastic.co/u/Alaa_Ksontini)\
**Post date:** [November 16, 2018, 2:43pm UTC](https://discuss.elastic.co/t/drop-event-when-regexp-dropping-every-event-apache2-module/157084/1 "2018-11-16T14:43:02Z")

</div>

Hi everyone,

I wanted to limit the number of documents stored in Elasticsearch. So I configured a processor in my filebeat.yml at the top-level. My input is the apache2 module which is configured fine.

```
processors:
    - drop_event:
        when:
           regexp:
               apache2.access.url: '\/(tag|track)\?'

```

I want to drop events where the url looks like this

- `/tag?something=value...`
- `/track?something=value...`

Here is a sample input:

`172.31.29.163 - - [16/Nov/2018:13:56:17 +0000] "GET /tag?something=value HTTP/1.1" 200 724 "[referer]"[user-agent]"`

Can someone point me to what exactly I'm doing wrong?  
Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2018, 2:43pm UTC](https://discuss.elastic.co/t/drop-event-when-regexp-dropping-every-event-apache2-module/157084/2 "2018-12-14T14:43:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
