# Filter only required logs and send to elastic search

**URL:** <https://discuss.elastic.co/t/filter-only-required-logs-and-send-to-elastic-search/271738>\
**Category:** Logstash\
**Created:** [April 30, 2021, 5:39am UTC](https://discuss.elastic.co/t/filter-only-required-logs-and-send-to-elastic-search/271738 "2021-04-30T05:39:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ELK\_gj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk_gj/32/79638_2.png) [@ELK\_gj](https://discuss.elastic.co/u/ELK_gj)\
**Post date:** [April 30, 2021, 5:39am UTC](https://discuss.elastic.co/t/filter-only-required-logs-and-send-to-elastic-search/271738/1 "2021-04-30T05:39:37Z")

</div>

Hi,

My input file contains 10 lines of logs, out of which need to parse only 5 logs based on a string, say example: NAS.  
So, out of 10 logs only 5 logs which contains keyword "NAS" should parse and go to elasticsearch.  
I couldn't find any suitable filter for this. Can you please help me suggesting a filter.  
Thanks in advance.

My log format:

```auto
000331 Tue Mar 30 09:21:07 2021 7F9ACBCCC700 INFO NAS tasks/nas/nas_proc.c :0309 Received NAS UPLINK DATA IND from S1AP for ue_id = (1)
000332 Tue Mar 30 09:21:07 2021 7F9ACBCCC700 INFO NAS-EM tasks/nas/emm/sap/emm_as.c :0176 EMMAS-SAP - Received primitive EMMAS_DATA_IND (214)
000333 Tue Mar 30 09:21:07 2021 7F9ACBCCC700 INFO NAS-EM tasks/nas/emm/sap/emm_as.c :0621 EMMAS-SAP - Received AS data transfer indication (ue_id=0x00000001, delivered=true, length=19)

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 30, 2021, 3:32pm UTC](https://discuss.elastic.co/t/filter-only-required-logs-and-send-to-elastic-search/271738/2 "2021-04-30T15:32:59Z")

</div>

If you want to drop any message that does not contain the string "NAS" you could use

```
if "NAS" not in [message] { drop {} }

```

If you want to drop any event where [message] does not contain the word "NAS" you could use

```
if [message] !~ /\bNAS\b/ { drop {} }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2021, 3:33pm UTC](https://discuss.elastic.co/t/filter-only-required-logs-and-send-to-elastic-search/271738/3 "2021-05-28T15:33:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
