# Filtering logs thorugh fleet server

**URL:** <https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795>\
**Category:** Community Ecosystem\
**Created:** [January 29, 2025, 4:16am UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795 "2025-01-29T04:16:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohit\_Verma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohit_verma1/32/140968_2.png) [@Mohit\_Verma1](https://discuss.elastic.co/u/Mohit_Verma1)\
**Post date:** [January 29, 2025, 4:16am UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795/1 "2025-01-29T04:16:22Z")

</div>

I have installed **Elastic Agent** on multiple servers to collect logs and send them to Elasticsearch via **Fleet Server**. I want to filter logs at the source so that only **error-level logs** are collected and sent, instead of collecting all logs and filtering them later in Elasticsearch.

I am using **Fleet Server** to manage Elastic Agents and have added the **Elasticsearch Logs** integration. My questions are:

1. **Can I configure the log filtering centrally from Fleet Server so that all agents collect only `error` level logs?**
2. **Where should I apply this filtering?** Should it be done in the Fleet integration settings, or do I need to manually configure each Elastic Agent?
3. **What is the correct way to implement this filtering?** Would adding a `drop_event` processor in the integration’s advanced settings work?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 29, 2025, 4:32am UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795/2 "2025-01-29T04:32:20Z")

</div>

Drop\_even is available and appropriate for simple logic. Look for examples and test.

---

<div class="post-metadata">

**Author:** ![Mohit\_Verma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohit_verma1/32/140968_2.png) [@Mohit\_Verma1](https://discuss.elastic.co/u/Mohit_Verma1)\
**Post date:** [January 29, 2025, 5:48am UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795/3 "2025-01-29T05:48:14Z")

</div>

![Screenshot from 2025-01-29 11-17-27](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1ce6433d67b17990ac352bba2e81f9a84e45ba33.png)

Can you tell me where we should add drop\_event

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 29, 2025, 5:13pm UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795/4 "2025-01-29T17:13:36Z")

</div>

That integration doesn't seem to have the Advanced section, so you can't add processors. I hadn't noticed that this integration is different.

You would have to change the policy logging level in the setting, advanced setting, agent logging level. Others have had problems where this change doesn't take effect, so on each agent, go to the bottom of the logging page, change the level and click apply changes. I think that should be a bug, but it hasn't gained traction to be one.

If you have 1000's of agents, an ingest policy drop might be easier. I think you would create ingest pipeline logs-elastic\_agent.filebeat@custom

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 29, 2025, 5:19pm UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795/5 "2025-01-29T17:19:34Z")

</div>

> <https://github.com/elastic/kibana/issues/158861>
>
> Currently in Fleet the agent log level can only be changed per agent. It would b…e more convenient to be able to change the log level for every agent assigned to a specific policy. Often this is done to reduce the amount of logs generated by agents to make monitoring more cost effective (for example defaulting all agents to the warning level instead of info).
> 
> The agent policy exposes the ability to do this but it isn't possible to change it in Fleet. https://github.com/elastic/elastic-agent/blob/fdc46bffaa744f7916d64112b1b52d836f25f6d1/elastic-agent.reference.yml#L175-L177
> 
> \`\`\`yaml
> \# Sets log level. The default log level is info.
> \# Available log levels are: error, warning, info, debug
> \#agent.logging.level: info
> \`\`\`
> 
> See some requests for this in the comments on https://github.com/elastic/elastic-agent/issues/2212#issuecomment-1434439679.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2025, 5:20pm UTC](https://discuss.elastic.co/t/filtering-logs-thorugh-fleet-server/373795/6 "2025-02-26T17:20:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
