# Filter Not Working (Version 2.3.1)

**URL:** <https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889>\
**Category:** Logstash\
**Created:** [May 1, 2016, 3:29pm UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889 "2016-05-01T15:29:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![VenkataMR](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@VenkataMR](https://discuss.elastic.co/u/VenkataMR)\
**Post date:** [May 1, 2016, 3:29pm UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889/1 "2016-05-01T15:29:49Z")

</div>

New to Logstash, was trying to filer certain messages which have matching either of INFO, ERROR, WARNING and having time stamp in certain format only. I don't want any other message by having bellow filter.

`filter { date { match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"] } grok { match => ["message" , "INFO"] } grok { match => ["message" , "ERROR"] } grok { match => ["message" , "WARNING"] } }`  
But i see messages like below were as well getting filtered.  
`qqqqqqqqqqqqqqqqqqqqqqqqq` or `aaaaaaaaaaaaaaaaaaaaaaa`

Something missing in the filter?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 1, 2016, 10:28pm UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889/2 "2016-05-01T22:28:06Z")

</div>

So you don't want messages with INFO/ERROR?WARNING, and with that date format to be processed?

---

<div class="post-metadata">

**Author:** ![VenkataMR](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@VenkataMR](https://discuss.elastic.co/u/VenkataMR)\
**Post date:** [May 2, 2016, 2:05am UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889/3 "2016-05-02T02:05:23Z")

</div>

I want messages which contain INFO or ERROR or WARNING or having timestamp to be filtered to output. Rest all messages should be stopped for writing to output stream.

---

<div class="post-metadata">

**Author:** ![VenkataMR](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@VenkataMR](https://discuss.elastic.co/u/VenkataMR)\
**Post date:** [May 5, 2016, 12:51pm UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889/4 "2016-05-05T12:51:03Z")

</div>

Any issue with the configuration

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 5, 2016, 5:09pm UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889/5 "2016-05-05T17:09:35Z")

</div>

grok is useful to transform an unstructured message to a document.  
It's not done to remove some messages.

If you want to do that :

```
if [message] !~ "INFO|WARNING|ERROR" {
  drop{}
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/filter-not-working-version-2-3-1/48889/6 "2017-07-06T04:59:14Z")

</div>


