# Drop logs from particular hostname

**URL:** <https://discuss.elastic.co/t/drop-logs-from-particular-hostname/137355>\
**Category:** Logstash\
**Created:** [June 26, 2018, 4:47am UTC](https://discuss.elastic.co/t/drop-logs-from-particular-hostname/137355 "2018-06-26T04:47:16Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2018, 6:36am UTC](https://discuss.elastic.co/t/drop-logs-from-particular-hostname/137355/2 "2018-06-26T06:36:43Z")

</div>

You can wrap a drop filter in a conditional that checks the content of a field. Some examples:

> [@Drop some line when match in logstash](https://discuss.elastic.co/t/drop-some-line-when-match-in-logstash/80270):
>
> At the moment i have this filter working to drop some lines ## var\_log\_messages filter filter { if [type] == "var\_log\_messages" { grok { patterns\_dir =\> ["/etc/logstash/patterns/"] match =\> { "message" =\> "%{SYSLOGTIMESTAMP:var\_log\_messages\_timestamp} %{SYSLOGHOST:var\_log\_messages\_hostname} %{DATA:syslog\_program}(?:\[%{POSINT:var\_log\_secure\_pid}\])?: %{GREEDYDATA:message}" } overwrite…

> <https://stackoverflow.com/questions/27443392/how-can-i-have-logstash-drop-all-events-that-do-not-match-a-group-of-regular-exp>

> [@How to exclude bad output (lines not matching 'grok' pattern) from logstash?](https://discuss.elastic.co/t/how-to-exclude-bad-output-lines-not-matching-grok-pattern-from-logstash/40459):
>
> I have a log file and I am parsing it through Logstash and storing it in some place. But the the problem is that some lines in the log file do not always match my grok pattern and are therefore tagged as 'grokparsefailure' etc automatically. I do not tag any line explicitly, so the lines which are automatically tagged by logstash are the wrongly structured lines and I want these lines to be skipped i.e. I don't want these output lines to appear in the output at all (lines which have tags). Can …

> **[Accessing event data and fields | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)**

---

_[View the full topic](https://discuss.elastic.co/t/drop-logs-from-particular-hostname/137355)._
