# Help with drop\_event

**URL:** <https://discuss.elastic.co/t/help-with-drop-event/240763>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [July 10, 2020, 9:21pm UTC](https://discuss.elastic.co/t/help-with-drop-event/240763 "2020-07-10T21:21:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nwed](https://avatars.discourse-cdn.com/v4/letter/n/dbc845/32.png) [@nwed](https://discuss.elastic.co/u/nwed)\
**Post date:** [July 10, 2020, 9:21pm UTC](https://discuss.elastic.co/t/help-with-drop-event/240763/1 "2020-07-10T21:21:33Z")

</div>

We are just starting to play around with drop\_event filtering. Auditd rules are not great at filtering so drop\_event is going to serve us well.

Right now we are stuck with a nesting example and want to know what is possible. Any suggestions are appreciated

```auto
processors:
    - drop_event.when.and:
      - regexp.tags: redacted
      - or:
        - equals.process.executable: /opt/Tools/redacted
        - equals.process.executable: /usr/sbin/redacted2
          - or:
            - equals.auditd.data.syscall: unlink
            - equals.auditd.data.syscall: rename

```

Right now, the first and + or statements work. For the second or statement, this is what's not accepted. We want the syscalls to be matched only when the second executable is matched.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2020, 11:21pm UTC](https://discuss.elastic.co/t/help-with-drop-event/240763/2 "2020-08-07T23:21:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
