# Input Filtering on fields or bpf filter before sending to elastic

**URL:** https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716
**Category:** Beats
**Tags:** packetbeat
**Created:** [August 3, 2015, 12:15pm UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716 "2015-08-03T12:15:20Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Alexandre\_Derumier](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Alexandre\_Derumier](https://discuss.elastic.co/u/Alexandre_Derumier)
#### Post date: [August 3, 2015, 12:15pm UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/1 "2015-08-03T12:15:20Z")

</div>

Hi,

I would like to known if it's possible to filter data in packetbeat, based on protocol fields.  
For example, I would like to exclude some ips from client\_ip or host from http.request\_headers.host.

Also, is it possible to configure bpf filters on interfaces ?

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [August 3, 2015, 12:23pm UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/2 "2015-08-03T12:23:17Z")

</div>

For now the short answer is 'no' to both questions.

We want to have filtering in beats, but we're still looking for the best way to do it.

There is an implicit BPF filter set by Packetbeat (computed from the ports configured in the configuration file) but there's currently no way to explicitly set it. Adding this should be fairly easy, we'd welcome a pull request for it if you want to play with it.

---

<div class="post-metadata">

### Author: ![Alexandre\_Derumier](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Alexandre\_Derumier](https://discuss.elastic.co/u/Alexandre_Derumier)
#### Post date: [August 4, 2015, 6:49am UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/3 "2015-08-04T06:49:02Z")

</div>

Thanks for the reply,  
I was trying bpf\_filter: and didn't understand why it was not working.

I'll try to have a look at it, it should be easy to define a custom bpf\_filter and add something like  
bpf\_filter += "and port ...."

---

<div class="post-metadata">

### Author: ![Alexandre\_Derumier](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Alexandre\_Derumier](https://discuss.elastic.co/u/Alexandre_Derumier)
#### Post date: [August 4, 2015, 7:21am UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/4 "2015-08-04T07:21:16Z")

</div>

I'm never code with go language, but maybe a simple

func (sniffer \*SnifferSetup) Init(test\_mode bool, events chan common.MapStr) error {

- config.ConfigSingleton.Interfaces.Bpf\_filter = tcp.BpfFilter()

- config.ConfigSingleton.Interfaces.Bpf\_filter += tcp.BpfFilter()

could work ?

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [August 10, 2015, 4:39pm UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/5 "2015-08-10T16:39:07Z")

</div>

I did something like this as part of this [pull request](https://github.com/elastic/packetbeat/pull/194), more precisely [here](https://github.com/elastic/packetbeat/pull/194/files#diff-b15fcbf237f4c228c3e40ff2a27f04d5R209). However, instead of attempting to combine the two filters, I just made the user supplied one overwrite the existing one. This is because combining them is easy with simple examples but gets complex with VLANs, multiple conditions, etc.

---

<div class="post-metadata">

### Author: ![aros](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@aros](https://discuss.elastic.co/u/aros)
#### Post date: [September 18, 2015, 6:34am UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/6 "2015-09-18T06:34:47Z")

</div>

I like the idea of being able to filter too. One use case could be to actually store request values depending on response code. I don't have to store response body or request parameter (is there a way to actually save request body of POST request as well? Haven't figured it out yet) for a request returning 200 code, but I want to know what the complete request is in case of failure. So filtering depending on response code would be awesome!

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [September 18, 2015, 7:36am UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/7 "2015-09-18T07:36:31Z")

</div>

We agree this is important and we'll be adding a flexible way of filtering to support use cases like this. But I don't have an ETA yet.

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [September 25, 2015, 10:11am UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/8 "2015-09-25T10:11:49Z")

</div>

You can follow the status of this feature request in Github: [https://github.com/elastic/libbeat/issues/111](https://github.com/elastic/libbeat/issues/111)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:58pm UTC](https://discuss.elastic.co/t/input-filtering-on-fields-or-bpf-filter-before-sending-to-elastic/26716/9 "2017-07-05T21:58:43Z")

</div>


