# Drop events if a field does not exist

**URL:** <https://discuss.elastic.co/t/drop-events-if-a-field-does-not-exist/111034>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 11, 2017, 8:41am UTC](https://discuss.elastic.co/t/drop-events-if-a-field-does-not-exist/111034 "2017-12-11T08:41:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vivekthangathurai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivekthangathurai/32/23561_2.png) [@vivekthangathurai](https://discuss.elastic.co/u/vivekthangathurai)\
**Post date:** [December 11, 2017, 8:41am UTC](https://discuss.elastic.co/t/drop-events-if-a-field-does-not-exist/111034/1 "2017-12-11T08:41:21Z")

</div>

I would like drop events if a field does not exist in the doc.  
will the drop\_events config help here?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 11, 2017, 2:10pm UTC](https://discuss.elastic.co/t/drop-events-if-a-field-does-not-exist/111034/2 "2017-12-11T14:10:05Z")

</div>

You could try the `regex` condition. It would keep every event if `your.field` contains anything.

```auto
processors:
 - drop_event:
       when:
           not:
               regexp:
                   your.field: ".*"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 2:10pm UTC](https://discuss.elastic.co/t/drop-events-if-a-field-does-not-exist/111034/3 "2018-01-08T14:10:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
