# Logstash filter issue

**URL:** <https://discuss.elastic.co/t/logstash-filter-issue/47065>\
**Category:** Logstash\
**Created:** [April 12, 2016, 3:01am UTC](https://discuss.elastic.co/t/logstash-filter-issue/47065 "2016-04-12T03:01:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)\
**Post date:** [April 12, 2016, 3:01am UTC](https://discuss.elastic.co/t/logstash-filter-issue/47065/1 "2016-04-12T03:01:38Z")

</div>

I try to parse the log.  
if the log "didn't" have 'specific' like as follow logstash prints ,then will be drop the event This is what logstash prints:

{  
"message" =\> "...",  
"host" =\> "10.10.10.20",  
"@version" =\> "1",  
"@timestamp" =\> "2016-04-12T02:28:18.233Z",  
"type" =\> "snmptrap",  
"1\_3\_6\_1\_2\_1\_1\_3\_0" =\> "21 days, 17:08:57.94",  
"1\_3\_6\_1\_6\_3\_1\_1\_4\_1\_0" =\> "specific::userdefined",  
}

I can only specify the content of the field (prefix is specific) rather than its field name (1\_3\_6\_1\_6\_3\_1\_1\_4\_1\_0) ,so how to parser the log to filter and to drop the event?  
What do I need to do?  
If anyone knows how to do with it , please help. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:02am UTC](https://discuss.elastic.co/t/logstash-filter-issue/47065/2 "2017-07-06T05:02:52Z")

</div>


