Dropping multiple windows events in logstash


(Raj) #1

Hi There ,

Iam trying to drop multiple events in logstash , how to implement it

As of now i use two different filters , but I want it in one filter

filter {

  if "windows_ad" in [tags] {

   if [event_id] == 5157 {

       drop { }

     }

  }

}

I tried this it doesnt work

filter {

  if "windows_ad" in [tags] {

   if [event_id] == ["5157", "5158"] {

       drop { }

     }

  }

}

Could any one help me to execute it


(Saifeddine Hmissi) #2

Hello ,
if [event_id] in ['5157', '5158']


(Raj) #3

No I Have tried that as well ,it doesnt work


(Hari Haran) #4

Can you try this

if [5157 ] or [5158]


(Raj) #5

You mean like this

filter {

if "windows_ad" in [tags] {

if [5157 ] or [5158] in [event_id]

{

   drop { }

 }

}

}

and i tried with quotes as well like this

if " [5157 ] or [5158] " in [event_id]

it doesnt work


(Saifeddine Hmissi) #6

the type of [event_id] is text ?


(system) #7

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.