# Logstash filter not working. Probably my fault :D

**URL:** <https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811>\
**Category:** Logstash\
**Created:** [October 30, 2017, 9:30pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811 "2017-10-30T21:30:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![motts](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@motts](https://discuss.elastic.co/u/motts)\
**Post date:** [October 30, 2017, 9:30pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811/1 "2017-10-30T21:30:46Z")

</div>

I am new to logstash, but I have read a few things on it. I am experimenting with Server 2003 logs. I am stuck on a particular filter configuration, but when I run configtest, everything comes back as OK. I go to check Kibana and the filter doesn't seem to be working as intended. Here is my filter:

filter {

if [type] == "Windows2003" {

mutate {

add\_tag =\> ["Server2003"]  
}

if "538" in [EventID] {

drop {}  
}  
}

The tag is added to all the entries, but all of the 538 Windows events are still there.

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eef02d83780ecb7a24f9aad047e5276f9677a591.png)

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 31, 2017, 6:07am UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811/2 "2017-10-31T06:07:21Z")

</div>

> if "538" in [EventID] {

Change to:

```
if [EventID] == 538 {

```

Numeric values should be compared to numeric literals.

---

<div class="post-metadata">

**Author:** ![motts](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@motts](https://discuss.elastic.co/u/motts)\
**Post date:** [October 31, 2017, 4:49pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811/3 "2017-10-31T16:49:47Z")

</div>

Worked like a charm, thanks. Now I am trying to keep rules, so I wrote this and it works fine.

if [EventID] != 538 { drop{} }

However, I would like to add multiple events to that list.

I have tried:

if [EventID] != 538 or [EventID] != 528 {

and this one

if [EventID] != 538 or 528 {

but no events seem to be recording now. Logstash is running fine, with no errors so that leaves my logic to be the problem. So what I am really after, is there a way to drop bulk windows events from being shipped to Elasticsearch? We'd like to have all the events sent to Logstash in case we'd like to monitor those events, but at this time, we wish to not record them in ELK.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 31, 2017, 8:18pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811/4 "2017-10-31T20:18:37Z")

</div>

> if [EventID] != 538 or [EventID] != 528 {

`and`, not `or`. If you think about it, the expression above is _always_ true. Do this instead:

```
if [EventID] not in [528, 538] {

```

> So what I am really after, is there a way to drop bulk windows events from being shipped to Elasticsearch? We'd like to have all the events sent to Logstash in case we'd like to monitor those events, but at this time, we wish to not record them in ELK.

Just wrap the elasticsearch output in a conditional instead of wrapping a drop filter in a conditional.

---

<div class="post-metadata">

**Author:** ![motts](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@motts](https://discuss.elastic.co/u/motts)\
**Post date:** [October 31, 2017, 8:51pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811/5 "2017-10-31T20:51:48Z")

</div>

Also worked like a charm.

At the start of my filter, I put:

filter {

if [EventID] not in [528, 538] {  
drop {}  
}

- and then the rest of the filter\*

I found this drastically increased performance rather than having the drop at the end of the filter so that all the unwanted events were not getting parsed and then dropped. It does not seem like much, but when you are handling thousands of devices with potentially thousands events, that adds up really quick.

Many thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2017, 8:51pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working-probably-my-fault-d/105811/6 "2017-11-28T20:51:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
