# Drop filter in logstash with filebeat pipelines

**URL:** <https://discuss.elastic.co/t/drop-filter-in-logstash-with-filebeat-pipelines/218309>\
**Category:** Logstash\
**Created:** [February 7, 2020, 9:52am UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-with-filebeat-pipelines/218309 "2020-02-07T09:52:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![old\_chocobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/old_chocobo/32/62268_2.png) [@old\_chocobo](https://discuss.elastic.co/u/old_chocobo)\
**Post date:** [February 7, 2020, 9:52am UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-with-filebeat-pipelines/218309/1 "2020-02-07T09:52:39Z")

</div>

Hello,

I have a Filebeat+Logstash+Elasticsearch stack, it is working nice. I am using Filebeat module pipelines in Elasticsearch because I want to use default Filebeat dashboards in Kibana.

Now I need to drop some log lines in Logstash but it is not working. This is my Logstash config:

```
input {
  beats {
    port => "redacted"
    ssl => true
    ssl_certificate_authorities => ["/redacted.crt"]
    ssl_certificate => "/redacted.crt"
    ssl_key => "/redacted.key"
    ssl_verify_mode => "force_peer"
  }
}

filter {
  # Drop named denys:
  if [message] =~ /^client.*query\ \(cache\).*denied$/ {
    drop { }
  }
}

output {
  if [@metadata][pipeline] {
    elasticsearch {
      user => "redacted"
      password => "redacted"
      hosts => "https://redacted.example.com:redated"
      manage_template => false
      ilm_enabled => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}"
      pipeline => "%{[@metadata][pipeline]}"
    }
  } else {
    elasticsearch {
      user => "reacted"
      password => "redacted"
      hosts => "https://redacted.example.com:redacted"
      manage_template => false
      ilm_enabled => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}"
    }
  }
}

```

Any ideas? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![old\_chocobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/old_chocobo/32/62268_2.png) [@old\_chocobo](https://discuss.elastic.co/u/old_chocobo)\
**Post date:** [February 7, 2020, 10:43am UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-with-filebeat-pipelines/218309/2 "2020-02-07T10:43:29Z")

</div>

I just saw that if I do not use regex it is working:

```
  if "denied" in [message] {
    drop { }
  }

```

Anyway, I need to use regex, so any idea about what could be wrong?

---

<div class="post-metadata">

**Author:** ![old\_chocobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/old_chocobo/32/62268_2.png) [@old\_chocobo](https://discuss.elastic.co/u/old_chocobo)\
**Post date:** [February 7, 2020, 12:24pm UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-with-filebeat-pipelines/218309/3 "2020-02-07T12:24:00Z")

</div>

Finally the issue only was a bad regex u\_u

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 12:24pm UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-with-filebeat-pipelines/218309/4 "2020-03-06T12:24:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
