# How can I check event.field value from a file?

**URL:** <https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292>\
**Category:** Logstash\
**Created:** [March 15, 2021, 4:52pm UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292 "2021-03-15T16:52:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ishaan](https://avatars.discourse-cdn.com/v4/letter/i/f9ae1b/32.png) [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Post date:** [March 15, 2021, 4:52pm UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292/1 "2021-03-15T16:52:19Z")

</div>

How can I check if the event.field\_name value is present in the file? If yes, drop the event otherwise send the event to elasticsearch.

Note: The field\_name could have multiple values in that file, and I want to check if the field\_name value is present among the multiple values in that file.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 15, 2021, 7:42pm UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292/2 "2021-03-15T19:42:56Z")

</div>

You can add a [conditional statement](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals) in your filter and then [drop](https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html) the event if it matches.

Something like the below.

```auto
    filter {
      if [event.field_name] == "value" {
        drop { }
      }
    }

```

---

<div class="post-metadata">

**Author:** ![Ishaan](https://avatars.discourse-cdn.com/v4/letter/i/f9ae1b/32.png) [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Post date:** [March 15, 2021, 8:47pm UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292/3 "2021-03-15T20:47:10Z")

</div>

Can we compare with the value present in a file (local storage)?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 15, 2021, 8:57pm UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292/4 "2021-03-15T20:57:34Z")

</div>

Yes. If you know all the options for the name you can do something like

```auto
    filter {
      if [fieldname] or [fieldname2] or [anotherway] or [afourth] {
        drop { }
      }
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 16, 2021, 1:27am UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292/5 "2021-03-16T01:27:19Z")

</div>

Your question is not entirely clear, but if you are asking what I think you are asking you might be able to do it with a [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter, otherwise you could do it in ruby, use the init option to load the file, build an array of entries, then test array membership in the code option and call event.cancel if you want to drop the event.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2021, 1:27am UTC](https://discuss.elastic.co/t/how-can-i-check-event-field-value-from-a-file/267292/6 "2021-04-13T01:27:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
