# Drop if message contains text from a List of Strings

**URL:** <https://discuss.elastic.co/t/drop-if-message-contains-text-from-a-list-of-strings/142102>\
**Category:** Logstash\
**Created:** [July 30, 2018, 6:48am UTC](https://discuss.elastic.co/t/drop-if-message-contains-text-from-a-list-of-strings/142102 "2018-07-30T06:48:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Waleed\_Malik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waleed_malik/32/33832_2.png) [@Waleed\_Malik](https://discuss.elastic.co/u/Waleed_Malik)\
**Post date:** [July 30, 2018, 6:48am UTC](https://discuss.elastic.co/t/drop-if-message-contains-text-from-a-list-of-strings/142102/1 "2018-07-30T06:48:34Z")

</div>

Hi,

I have a pre-defined set of Strings that i want to hard code in the conf file.

> if "some text " in [message] or "some text" in [message] {  
> drop {}  
> }

I want to create an array of strings and loop through them accordingly, and whenever there is a string match i want to drop that particular event.

I have tried with the ruby scripts but for me it was not working.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [August 7, 2018, 4:30pm UTC](https://discuss.elastic.co/t/drop-if-message-contains-text-from-a-list-of-strings/142102/2 "2018-08-07T16:30:09Z")

</div>

Have a look at the regex option in the translate filter (bonus, you can load your blacklist from a file).  
If you want the whole of the `message` field value to match the translate "key" then set `regex => false`.  
Example:

```auto

input {
  generator {
    lines => [
      '222101333',
      '123456789',
      'abc103def',
      'xyz301mno'
    ]
    count => 1
  }
}

filter {
  translate {
    field => "[message]"
    destination => "[matched]"
    dictionary => [ "100", "drop",
                     "101", "drop",
                     "102", "drop",
                     "103", "drop" ]
    exact => true
    regex => true
  }
  if [matched] == "drop" {
    drop {}
  }
}

output {
  stdout {
    codec => rubydebug {metadata => true}
  }
}

```

Output:

```auto
{
      "sequence" => 0,
    "@timestamp" => 2018-08-07T16:24:00.311Z,
      "@version" => "1",
          "host" => "Elastics-MacBook-Pro.local",
       "message" => "123456789"
}
{
      "sequence" => 0,
    "@timestamp" => 2018-08-07T16:24:00.312Z,
      "@version" => "1",
          "host" => "Elastics-MacBook-Pro.local",
       "message" => "xyz301mno"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2018, 4:30pm UTC](https://discuss.elastic.co/t/drop-if-message-contains-text-from-a-list-of-strings/142102/3 "2018-09-04T16:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
