I'm trying to drop events with multiple words like
Tuple, TUPLE, tuple
Complete config doesn't seem to work with one word filter too
filebeat: registry_file: /var/run/filebeat/.gl-filebeat-registry spool_size: 2048 prospectors: - paths: - /opt/cargovan/storm/apache-storm-1.0.2/logs/workers-artifacts/*/*/worker.log input_type: log ignore_older: 10m close_older: 5m max_bytes: 2097152 fields: OO_CLOUD: test-cloud fields_under_root: false tail_files: false processors: - drop_event: when: regexp: message: 'TUPLE' output: logstash: hosts: ['test-url:5044'] loadbalance: true worker: 2 max_retries: -1 bulk_max_size: 2048 logging: level: warning to_files: false to_syslog: true
Also tried using with multiple words like below
processors: - drop_event: when: regexp: message: 'TUPLE' message: 'Tuple'