# Elastic-agent cloudflare logpull and problem with using processors for filter events

**URL:** <https://discuss.elastic.co/t/elastic-agent-cloudflare-logpull-and-problem-with-using-processors-for-filter-events/312069>\
**Category:** Elastic Agent\
**Tags:** filebeat\
**Created:** [August 14, 2022, 9:29pm UTC](https://discuss.elastic.co/t/elastic-agent-cloudflare-logpull-and-problem-with-using-processors-for-filter-events/312069 "2022-08-14T21:29:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![slast](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@slast](https://discuss.elastic.co/u/slast)\
**Post date:** [August 14, 2022, 9:29pm UTC](https://discuss.elastic.co/t/elastic-agent-cloudflare-logpull-and-problem-with-using-processors-for-filter-events/312069/1 "2022-08-14T21:29:42Z")

</div>

Hi Everyone  
I have a problem with elastic-agent( ver 7.17.4) that we are using to collect logs from cloudflare.  
I want to drop some events by using processors in "Edit Cloudflare integration" - but nothing is work. In "Cloudflare integration" i see that " Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent **before** the logs are parsed. May be i used wrong fields . Please help if you know.  
Here is some examples that i used to drop events:

1. I want to drop all events that has not field cloudflare.firewall.actions

processors:

- drop\_event:  
when:  
not:  
has\_fields: ['cloudflare.firewall.actions']

1. I want to drop all events when cloudflare.edge.pathing.src: "test"  
processors:

- drop\_event:  
when:  
equals:  
cloudflare.edge.pathing.src: "test"

For now nothing is work

---

<div class="post-metadata">

**Author:** ![slast](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@slast](https://discuss.elastic.co/u/slast)\
**Post date:** [August 15, 2022, 10:43am UTC](https://discuss.elastic.co/t/elastic-agent-cloudflare-logpull-and-problem-with-using-processors-for-filter-events/312069/2 "2022-08-15T10:43:46Z")

</div>

I turn on Preserve original event to see original event from Cloudflare.  
After that we see that cloudflare.edge.pathing.src = EdgePathingSrc  
Answer:

processors:

- drop\_event:  
when:  
regexp:  
message: ""EdgePathingSrc":"test""

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2022, 8:15am UTC](https://discuss.elastic.co/t/elastic-agent-cloudflare-logpull-and-problem-with-using-processors-for-filter-events/312069/4 "2022-10-05T08:15:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
