# How to drop the following documents?

**URL:** <https://discuss.elastic.co/t/how-to-drop-the-following-documents/360449>\
**Category:** Logstash\
**Created:** [May 29, 2024, 10:58am UTC](https://discuss.elastic.co/t/how-to-drop-the-following-documents/360449 "2024-05-29T10:58:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bvoros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bvoros/32/5246_2.png) [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Post date:** [May 29, 2024, 10:58am UTC](https://discuss.elastic.co/t/how-to-drop-the-following-documents/360449/1 "2024-05-29T10:58:03Z")

</div>

Hello all,

I would like to match and drop the following documents but my filter fails to match these. I am trying to match against the "message" field, could or should I match against the "event" field?  
Can someone explain how this can be done?

Example doc:

```auto
{
  "_index": "index-2024.05.29",
  "_id": "jN3mw48BcV4jg42Il86T",
  "_version": 1,
  "_score": 0,
  "_source": {
    "@timestamp": "2024-05-29T10:30:20.125368176Z",
    "data": null,
    "event": {},
    "@version": "1",
    "message": "\n"
  },
  "fields": {
    "@timestamp": [
      "2024-05-29T10:30:20.125Z"
    ],
    "message.keyword": [
      "\n"
    ],
    "@version": [
      "1"
    ],
    "@version.keyword": [
      "1"
    ],
    "message": [
      "\n"
    ]
  }
}

```

and the relevant filter:

```auto
if [message] == "\\n" or [message] == "" or ![message] {
        drop {}
       }

```

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 29, 2024, 11:06am UTC](https://discuss.elastic.co/t/how-to-drop-the-following-documents/360449/2 "2024-05-29T11:06:03Z")

</div>

> [@bvoros](#):
>
> Hello all,
> 
> I would like to match and drop the following documents but my filter fails to match these. I am trying to match against the "message" field, could or should I match against the "event" field?  
> Can someone explain how this can be done?
> 
> Example doc:
> 
> ```auto
> {
> "_index": "index-2024.05.29",
> "_id": "jN3mw48BcV4jg42Il86T",
> "_version": 1,
> "_score": 0,
> "_source": {
> "@timestamp": "2024-05-29T10:30:20.125368176Z",
> "data": null,
> "event": {},
> "@version": "1",
> "message": "\n"
> },
> "fields": {
> "@timestamp": [
> "2024-05-29T10:30:20.125Z"
> ],
> "message.keyword": [
> "\n"
> ],
> "@version": [
> "1"
> ],
> "@version.keyword": [
> "1"
> ],
> "message": [
> "\n"
> ]
> }
> }
> 
> ```
> 
> and the relevant filter:
> 
> ```auto
> if [message] == "\\n" or [message] == "" or ![message] {
> drop {}
> }
> 
> ```

Hi,

try this:

```auto
if [message] == "\n" or [message] == "" or ![message] {
    drop {}
}

```

Regards

---

<div class="post-metadata">

**Author:** ![bvoros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bvoros/32/5246_2.png) [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Post date:** [May 29, 2024, 11:35am UTC](https://discuss.elastic.co/t/how-to-drop-the-following-documents/360449/3 "2024-05-29T11:35:58Z")

</div>

Hello and thank you, unfortunately no change in behaviour, the documents still show up.

---

<div class="post-metadata">

**Author:** ![bvoros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bvoros/32/5246_2.png) [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Post date:** [May 29, 2024, 11:55am UTC](https://discuss.elastic.co/t/how-to-drop-the-following-documents/360449/4 "2024-05-29T11:55:10Z")

</div>

As it turns out the solution was to enable escape sequences in logstash.yml.

config.support\_escapes: true

Thanks for your help
