# Filebeat + docker input - cannot drop events according to container name?

**URL:** <https://discuss.elastic.co/t/filebeat-docker-input-cannot-drop-events-according-to-container-name/167666>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 8, 2019, 4:26pm UTC](https://discuss.elastic.co/t/filebeat-docker-input-cannot-drop-events-according-to-container-name/167666 "2019-02-08T16:26:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nico\_Kruger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nico_kruger/32/40733_2.png) [@Nico\_Kruger](https://discuss.elastic.co/u/Nico_Kruger)\
**Post date:** [February 8, 2019, 4:26pm UTC](https://discuss.elastic.co/t/filebeat-docker-input-cannot-drop-events-according-to-container-name/167666/1 "2019-02-08T16:26:52Z")

</div>

I cannot for the life of me figure out why the following is not working:

This is using the elastic Filebeat 6.5.2 docker container:

```
filebeat.inputs:
- type: docker
  containers.ids: '*'
  combine_partial: true
  processors:
    - drop_event:
        when:
          equals:
            docker.container.name: "filebeat"

```

I literally want to not log anything related to the filebeat container. I've tried many combinations of getting an OR to work, using a regexp etc. but maybe someone can spot what I'm doing wrong with this simple example?

I expect the above to drop all log messages from the "filebeat" container.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2019, 4:27pm UTC](https://discuss.elastic.co/t/filebeat-docker-input-cannot-drop-events-according-to-container-name/167666/2 "2019-03-08T16:27:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
