# Filebeat Nginx module not dropping events

**URL:** <https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 13, 2018, 6:17pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797 "2018-12-13T18:17:11Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 21, 2018, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797/4 "2018-12-21T13:49:53Z")

</div>

I think the problem above is that `nginx.access.remote_ip` is only available after the ingest processor. The processing of the log line happens in Elasticsearch, so filebeat cannot filter based on this field as it never sees it.

For your case you would either have to do this in the ingest pipeline or do a regexp on the filebeat side with `exclude_line`: [https://www.elastic.co/guide/en/beats/filebeat/6.5/filebeat-input-log.html#filebeat-input-log-exclude-lines](https://www.elastic.co/guide/en/beats/filebeat/6.5/filebeat-input-log.html#filebeat-input-log-exclude-lines)

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797)._
