# Droping entire document

**URL:** <https://discuss.elastic.co/t/droping-entire-document/111097>\
**Category:** Logstash\
**Created:** [December 11, 2017, 1:26pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097 "2017-12-11T13:26:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [December 11, 2017, 1:26pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/1 "2017-12-11T13:26:16Z")

</div>

Hi All,

Iam monitoring the windows events using Beats , but i could find lot of events generated every second and its kind of overloaded

I want to drop this event id  
**event\_id : 5,516**  
Eventid is the field name and 5,516 is the value  
How to drop this documents completely wherever it have this eventid value, before it sends to elasticsearch.

Please help me in fixing this issue

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [December 11, 2017, 1:34pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/2 "2017-12-11T13:34:07Z")

</div>

Hi,

You can use the[drop filter](https://www.elastic.co/guide/en/logstash/5.5/plugins-filters-drop.html) (with the appropriate condition as per the example), so events are discarded.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [December 11, 2017, 1:44pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/3 "2017-12-11T13:44:06Z")

</div>

Thanks for the reply, actually I know the drop filter ,

could please tell me the exact filter condition ?

to remove all the document which has

**event\_id : 5,516**

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [December 11, 2017, 1:47pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/4 "2017-12-11T13:47:21Z")

</div>

```auto
filter { 
   if [event_id] == "5,516" { 
       drop { } 
   }
}
```

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [December 11, 2017, 1:48pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/5 "2017-12-11T13:48:52Z")

</div>

Thanks Paris 🙂 for the rocket reply, i will get back to you after implementing it

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [December 11, 2017, 2:16pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/6 "2017-12-11T14:16:14Z")

</div>

Hi Paris,

I tried this but am unsuccessful in dropping that event id, its still getting created

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [event\_id] == "5,516" {  
drop { }  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2017, 2:25pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/7 "2017-12-11T14:25:41Z")

</div>

Don't include the thousands separator in the condition. Also, make sure you check the data type of the `event_id` field. Is it an integer or a string? Look at the raw JSON document, available from the JSON tab in Kibana.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [December 11, 2017, 2:34pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/8 "2017-12-11T14:34:39Z")

</div>

Sure  
Thanks 🙂 for the input magnus, after removing the thousand separator it work fine 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 2:34pm UTC](https://discuss.elastic.co/t/droping-entire-document/111097/9 "2018-01-08T14:34:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
