# Event Filter \* field

**URL:** <https://discuss.elastic.co/t/event-filter-field/325674>\
**Category:** Elastic Security\
**Created:** [February 16, 2023, 2:28am UTC](https://discuss.elastic.co/t/event-filter-field/325674 "2023-02-16T02:28:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![NathanLau](https://avatars.discourse-cdn.com/v4/letter/n/e9a140/32.png) [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Post date:** [February 16, 2023, 2:28am UTC](https://discuss.elastic.co/t/event-filter-field/325674/1 "2023-02-16T02:28:47Z")

</div>

Hi all ,  
The purpose is refuse receive some logs.  
(Endpoint) there are a lot of event on everyday , don't want to receive not meaningful logs to occupied the space , how could filter all value of \* or filter the field?

It's not work

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62336549791292ecbe9b498e6e541b412975d876.png)

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [March 10, 2023, 7:16pm UTC](https://discuss.elastic.co/t/event-filter-field/325674/2 "2023-03-10T19:16:41Z")

</div>

Hi there!

If you would like to not receive alerts if a field is present, you can use the `exists` operator. If you would like to use wildcard matching, you can use the `matches` operator. I would suggest checking out the docs here that give a bit more detail on the operators.

If there are a list of values - say you only want to get alerted for some known ids or only get alerted if it is not one of those ids - you can also check out large value lists. You can upload a list of values and then create an exception using the `is in list/is not in list` operator. Docs for large value lists can be found [here](https://www.elastic.co/guide/en/security/current/value-lists-exceptions.html).

Hopefully that helps! Let us know if you need any further clarification or help on anything!

---

<div class="post-metadata">

**Author:** ![NathanLau](https://avatars.discourse-cdn.com/v4/letter/n/e9a140/32.png) [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Post date:** [March 13, 2023, 2:30am UTC](https://discuss.elastic.co/t/event-filter-field/325674/3 "2023-03-13T02:30:36Z")

</div>

Hi yctercero,

In event filter, there are only "is" "is not" "is one of" "is not one of" , no match or `is in list/is not in list` options.

---

<div class="post-metadata">

**Author:** ![WafaaNasr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wafaanasr/32/118373_2.png) [@WafaaNasr](https://discuss.elastic.co/u/WafaaNasr)\
**Post date:** [March 13, 2023, 3:59pm UTC](https://discuss.elastic.co/t/event-filter-field/325674/4 "2023-03-13T15:59:16Z")

</div>

Hi Nathan,

Thank you for clarifying that it is for the `Event filters`  
In that case, the available operators are

- `is`
- `is not`
- `is one of`
- `is not one of`
- `matches` =\> This is only available for the `file.path.text` field.

If you would like to filter using `wildcards`, you can use the `file.path.text` field. and if you would like to learn more about the `Event filters` please refer to this [docs](https://www.elastic.co/guide/en/security/current/event-filters.html).

Please let us know if this is helpful, or if you need any further assist!

---

<div class="post-metadata">

**Author:** ![NathanLau](https://avatars.discourse-cdn.com/v4/letter/n/e9a140/32.png) [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Post date:** [March 14, 2023, 1:12am UTC](https://discuss.elastic.co/t/event-filter-field/325674/5 "2023-03-14T01:12:04Z")

</div>

Simple to say, for some index, that a lot of useless field like agent\_id don't want to collect, but in event filter cannot only filtering the field like agent\_id with wildcards (\*) .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2023, 1:13am UTC](https://discuss.elastic.co/t/event-filter-field/325674/6 "2023-04-11T01:13:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
