# Drop logs on the basis \_jsonparsefailure

**URL:** <https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029>\
**Category:** Logstash\
**Created:** [October 4, 2018, 10:23am UTC](https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029 "2018-10-04T10:23:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bharat\_Gupta](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@Bharat\_Gupta](https://discuss.elastic.co/u/Bharat_Gupta)\
**Post date:** [October 4, 2018, 10:23am UTC](https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029/1 "2018-10-04T10:23:15Z")

</div>

"tags": [  
"beats\_input\_codec\_json\_applied",  
"\_jsonparsefailure"  
]

i want drop the log detail if get \_jsonparsefailure

i have applied this inside filter :-

if "\_jsonparsefailure" in [tags]{  
drop { }  
}

but still not resolving my problem i think it will apply only if single value "\_jsonparsefailure" inside the tags but in my case getting 2 values "beats\_input\_codec\_json\_applied", "\_jsonparsefailure"

give me appropriate solution

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2018, 4:57pm UTC](https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029/2 "2018-10-05T16:57:15Z")

</div>

> but still not resolving my problem i think it will apply only if single value "\_jsonparsefailure" inside the tags

No, not true.

The little piece of your configuration that you've showed us looks fine. Please show us the full configuration and an example document that should've been dropped but wasn't. Copy/paste from Kibana's JSON tab or use a `stdout { codec => rubydebug }` output to dump the raw event.

---

<div class="post-metadata">

**Author:** ![Bharat\_Gupta](https://avatars.discourse-cdn.com/v4/letter/b/0ea827/32.png) [@Bharat\_Gupta](https://discuss.elastic.co/u/Bharat_Gupta)\
**Post date:** [October 9, 2018, 6:24am UTC](https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029/3 "2018-10-09T06:24:22Z")

</div>

input {  
beats {  
port =\> 5044  
codec =\> json  
}  
}

filter {

if [tags] == ["beats\_input\_codec\_json\_applied","\_jsonparsefailure"] {  
drop { }  
}  
json {  
source =\> message  
}  
date  
{  
match =\> ["timestamp" , "ISO8601", "yyyy-MM-dd HH:mm:ss,SSS"]  
target =\> "@timestamp"  
}  
mutate {  
remove\_field =\> [message,json]  
}

```
}

```

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "demo-%{+YYYY.MM.dd}"  
document\_type =\> log  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 9, 2018, 6:41pm UTC](https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029/4 "2018-10-09T18:41:40Z")

</div>

Is it the json codec or the json filter that adds the `_jsonparsefailure` tag?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 6:41pm UTC](https://discuss.elastic.co/t/drop-logs-on-the-basis-jsonparsefailure/151029/5 "2018-11-06T18:41:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
