# Logstash drop() combinations

**URL:** <https://discuss.elastic.co/t/logstash-drop-combinations/109423>\
**Category:** Logstash\
**Created:** [November 28, 2017, 3:32pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423 "2017-11-28T15:32:19Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [November 28, 2017, 3:32pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/1 "2017-11-28T15:32:19Z")

</div>

Working with windows event logs, ML 'rare' function and trying to eliminate the 'fake rare' i.e. windows event logs that pop up and it's the same thing over and over again but with different random 'identifiers' in each line.

My question is how do I combine items in my .conf?

This works -  
filter {  
if "-type" in [message] { drop{ } }  
}

but how would I add multiple items in one drop like this, for some reason I can't seem to get this to work?

I haven't been able to find many examples of this either.

I want it to look something like this-  
filter {  
if "4688" in [[event.ID](http://event.ID)] AND "-type" OR "-log" in [message] { drop{ } }  
}

Thanks, if anyone has any better ideas about eliminating the 'fake rare' to find anomalies in 4688 command line data I'd appreciate that too!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 28, 2017, 3:39pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/2 "2017-11-28T15:39:35Z")

</div>

I suppose you'll want to say `[event][ID]` instead of `[event.ID]`. See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [November 28, 2017, 4:26pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/3 "2017-11-28T16:26:55Z")

</div>

Well, kind of like this but it doesn't work...  
filter {  
if [event\_id]== "4688" and ["-type","-log","Adobe","SCODEF","SecureConnector","CIT"] in [message] { drop{ } }  
}

event\_id is a field  
but I want to drop the event if ANY single item from the list is in the message. Like the list is a long list of or's, is this possible?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 28, 2017, 4:43pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/4 "2017-11-28T16:43:24Z")

</div>

How about a regexp then?

```
if ... and [message] =~ /(-type|-log|Adobe|...)/ {
```

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [November 29, 2017, 3:07pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/5 "2017-11-29T15:07:42Z")

</div>

Thanks Magnus!

That's really cool and pretty close, for some reason I can't get the event ID part to work...

This seems to work -  
filter {  
if [message] =~ /(-type|-log|Adobe|SCODEF|SecureConnector|CIT|CCM)/ { drop{} }  
}

but if I add the event id to it, it doesn't work -  
filter {  
if [event\_id] == "4,688" and [message] =~ /(-type|-log|Adobe|SCODEF|SecureConnector|CIT)/ { drop{} }  
}

and the event\_id does look like that -  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eba70e2ca7618453d0b54a3ad5e0cec193000476.png)

What am I missing?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 29, 2017, 3:23pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/6 "2017-11-29T15:23:03Z")

</div>

As the # at the beginning of the Kibana table row indicates `event_id` is a numeric field and not a string, hence:

```
if [event_id] == 4688 ...
```

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [November 30, 2017, 2:04pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/7 "2017-11-30T14:04:34Z")

</div>

Boom, you the man!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2017, 2:04pm UTC](https://discuss.elastic.co/t/logstash-drop-combinations/109423/8 "2017-12-28T14:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
