# How to ignore a specific IP?

**URL:** https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097
**Category:** Beats
**Tags:** packetbeat
**Created:** [February 14, 2017, 7:11pm UTC](https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097 "2017-02-14T19:11:05Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Ben\_Hoffman](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben\_Hoffman](https://discuss.elastic.co/u/Ben_Hoffman)
#### Post date: [February 14, 2017, 7:11pm UTC](https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097/1 "2017-02-14T19:11:05Z")

</div>

So I am doing a data visualization of netflow traffic, and I am running packetbeat in "af mode" to gather all of the netflow data.

The problem is that the IP that I am connecting to the box with packetbeat on it, is something I want to ignore. Since I know what it is and it is just cluttering things up in the visualization.

I want to ignore all of the traffic that has this data:

"dest.ip" of \< XYZ \>  
and  
"source.ip" of \< IP of server running packetbeat \>

I have the "packetbeat.ignore\_outgoing: true" set up in my packetbeat.yml file. I am running this on CentOS and outputting the packetbeat data straight to Logstash.

Is there any way to do this?

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [February 15, 2017, 11:19am UTC](https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097/2 "2017-02-15T11:19:05Z")

</div>

You should be able to use a custom [BPF filter](https://www.elastic.co/guide/en/beats/packetbeat/5.2/configuration-interfaces.html#_bpf_filter) for this. Something like `not ip ...`.Do note the limitations stated in the docs.

---

<div class="post-metadata">

### Author: ![Ben\_Hoffman](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben\_Hoffman](https://discuss.elastic.co/u/Ben_Hoffman)
#### Post date: [February 15, 2017, 7:25pm UTC](https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097/3 "2017-02-15T19:25:14Z")

</div>

What I ended up doing is writting a Logsash filter:

```
filter {
      if[type] == "flow" and [dest][ip] == "192.168.X.Y" and [packet_source][ip] == "192.168.Z.D" {
            drop { }
      }
}
```

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 16, 2017, 5:03pm UTC](https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097/4 "2017-02-16T17:03:14Z")

</div>

which packetbeat version? You can drop events from within packetbeat using processors. Filtering via BPF would be better. Reason is, you want to filter as early as possible. Filtering late, still requires you to process and analyse the traffic. Filtering out in logstash means packetbeat has to serialize and send events. Filtering early via BPF saves you some resources.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 16, 2017, 5:04pm UTC](https://discuss.elastic.co/t/how-to-ignore-a-specific-ip/75097/5 "2017-03-16T17:04:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
