# Filter Json on specific key

**URL:** <https://discuss.elastic.co/t/filter-json-on-specific-key/126222>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 30, 2018, 11:14am UTC](https://discuss.elastic.co/t/filter-json-on-specific-key/126222 "2018-03-30T11:14:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![eddie4](https://avatars.discourse-cdn.com/v4/letter/e/838e76/32.png) [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Post date:** [March 30, 2018, 11:14am UTC](https://discuss.elastic.co/t/filter-json-on-specific-key/126222/1 "2018-03-30T11:14:26Z")

</div>

Hello,

Am attempting to filter which lines of logs are being send to the backend. I have read up on the following documentation however i didn't find my answer.  
[https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html)  
[https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#exclude-lines](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#exclude-lines)

example json:  
{  
"timestamp": "2018-03-10T12:45:25.093419+0100",  
"flow\_id": 4.9497252168403e+14,  
"in\_iface": "lo",  
"event\_type": "alert",  
"src\_ip": "127.0.198.22",  
"src\_port": 80,  
"dest\_ip": "x.x.237.85",  
"dest\_port": 60618,  
"html": "html data"  
}  
Now i would like to filter on if src\_ip = 127.0.198.22. Now I could probably do this by filtering by line and entering the whole string("src\_ip": "127.0.198.22",). But I was hoping to be able to parse the json and filter line['src\_ip'] = 127.0.198.22 is this possible?

why?  
Regex can be a performance killer.  
Possible injection of data via the html field if it contains "src\_ip": "127.0.198.22",  
Bad practice

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [March 30, 2018, 12:41pm UTC](https://discuss.elastic.co/t/filter-json-on-specific-key/126222/2 "2018-03-30T12:41:07Z")

</div>

Hello @eddie4, I am not sure from your description if are you using [JSON parsing](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-input-log.html#filebeat-input-log-config-json) on Filebeat?

If you were you use the following without a regexp?

```auto
processors:
 - drop_event:
     when:
        contains:
           src_ip: "127.0.198.22"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2018, 12:41pm UTC](https://discuss.elastic.co/t/filter-json-on-specific-key/126222/3 "2018-04-27T12:41:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
