# Drop filter is not dropping the logs

**URL:** <https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781>\
**Category:** Logstash\
**Created:** [August 4, 2020, 7:56pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781 "2020-08-04T19:56:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [August 4, 2020, 7:56pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781/1 "2020-08-04T19:56:37Z")

</div>

I need to drop logs when syslog5424\_host is e.g dev.dev.sample-app-109, the number at the end will change but I have regex to accommodate that. This is my current configuration but it's not dropping the logs.

The field syslog5424\_host looks something like this:  
`dev.dev.sample-app-206, dev.dev.sample-app-206, dev.dev.sample-app-206`

```
filter {
  if [syslog5424_host] =~ /(dev\.dev\.sample-app-[0-9]{1,10},?\s?)+/ {
      mutate {
      add_tag => ["SampleApp"]
    }
  }

  if "SampleApp" in [tags] {
    drop { }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2020, 8:37pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781/2 "2020-08-04T20:37:02Z")

</div>

If you use

```
output { stdout { codec => rubydebug } }

```

then what do the [syslog5424\_host] and [tags] fields look like? (I am wondering if [syslog5424\_host] could be an array.)

---

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [August 5, 2020, 3:21pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781/3 "2020-08-05T15:21:53Z")

</div>

Sorry for replying so late I broke my ELK setup, yeah you are right its a array, how do I deal with array?

```
"syslog5424_host" => [
Aug 05 10:19:52 dc-elk-pr-log02 logstash[10169]: [0] "dev.dev.sample-app-206",
Aug 05 10:19:52 dc-elk-pr-log02 logstash[10169]: [1] "dev.dev.sample-app-206",
Aug 05 10:19:52 dc-elk-pr-log02 logstash[10169]: [2] "dev.dev.sample-app-206"
Aug 05 10:19:52 dc-elk-pr-log02 logstash[10169]: ],
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2020, 3:44pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781/4 "2020-08-05T15:44:36Z")

</div>

If there are always exactly three host entries then you could test each of them using

```
if [syslog5424_host][0] =~ /dev\.dev\.sample-app-[0-9]{1,10},?\s?/

```

etc. Alternatively, do it in ruby. Something like this (which I have not tested)

```
ruby {
    code => '
        matched = true
        hosts = event.get("syslog5424_host")
        if hosts.is_a? Array && hosts.length > 0
            hosts.each { |x|
                matched &= x.match?(/dev\.dev\.sample-app-[0-9]{1,10},?\s?/)
            }
            if matched { event.cancel }
        end
    '
}
```

---

<div class="post-metadata">

**Author:** ![srbhklkrn](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@srbhklkrn](https://discuss.elastic.co/u/srbhklkrn)\
**Post date:** [August 5, 2020, 4:19pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781/5 "2020-08-05T16:19:54Z")

</div>

Awesome!!! thank you so much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2020, 4:19pm UTC](https://discuss.elastic.co/t/drop-filter-is-not-dropping-the-logs/243781/6 "2020-09-02T16:19:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
