# Drop the complete message containing specific strings

**URL:** <https://discuss.elastic.co/t/drop-the-complete-message-containing-specific-strings/197799>\
**Category:** Logstash\
**Created:** [September 3, 2019, 9:07am UTC](https://discuss.elastic.co/t/drop-the-complete-message-containing-specific-strings/197799 "2019-09-03T09:07:18Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Klaus.Lucas](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@Klaus.Lucas](https://discuss.elastic.co/u/Klaus.Lucas)\
**Post date:** [September 3, 2019, 9:07am UTC](https://discuss.elastic.co/t/drop-the-complete-message-containing-specific-strings/197799/1 "2019-09-03T09:07:18Z")

</div>

Hello,

I have the following definition to drop messages from a log file containing strings and text:  
input {  
file {  
path =\> "/opt/mapr/logs/cldb.log"  
tags =\> "mapr\_cldb"  
codec =\> plain {charset =\> "ISO-8859-1"}  
}  
}

filter {  
if "INFO" in [message] { drop{ } }  
if "[CLDB-1]:" in [message] { drop{ } }  
if "reqIncoming" in [message] { drop{ } }  
if "The server has decided to close" in [message] { drop{ } }  
if "WARN log" in [message] { drop{ } }  
if "RpcProgram not found" in [message] { drop{ } }  
if "No such file or directory(2)" in [message] { drop{ } }  
if "attempting to become a master" in [message] { drop{ } }  
}  
}

I see now, that all "WARNING" messages will also be dropped.  
E.g:  
2019-08-31 01:22:26,389 WARN Alarms [HB-2]: composeEmailMessage: Alarm raised:

What is the correct definition for this scenario?

---

_[View the full topic](https://discuss.elastic.co/t/drop-the-complete-message-containing-specific-strings/197799)._
