# Metric and drop filter not working together

**URL:** <https://discuss.elastic.co/t/metric-and-drop-filter-not-working-together/286380>\
**Category:** Logstash\
**Created:** [October 11, 2021, 3:10pm UTC](https://discuss.elastic.co/t/metric-and-drop-filter-not-working-together/286380 "2021-10-11T15:10:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_Partapsing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_partapsing/32/95701_2.png) [@Rakesh\_Partapsing](https://discuss.elastic.co/u/Rakesh_Partapsing)\
**Post date:** [October 11, 2021, 3:10pm UTC](https://discuss.elastic.co/t/metric-and-drop-filter-not-working-together/286380/1 "2021-10-11T15:10:33Z")

</div>

Hi,

I would like throttle events using the logstash-filter-throttle plugin. After that to create a logstash-filter-metric to push it to prometheus using graphite exporter. And finally drop the events that are marked by the throttle plugin.  
The issue I face is when I use de drop plugin the metric event does not get created.  
Is there way to have both the drop filter and metric filter coexist?

```auto
filter {
        throttle {
          id => "main_throttle_filter"
          enable_metric => true
          before_count => -1
          after_count => 50
          period => 60
          max_age => 120
          key => "%{[fields][platform]}"
          add_tag => "throttled_events"
        }

        if "throttled_events" in [tags] {
          metrics {
            id => "throttled_metrics"
            meter => "logstash_throttled_total.%{[fields][platform]}"
            rates => []
            add_tag => "throttled_metrics"
            flush_interval => 30
            ignore_older_than => 120
          }

          drop {
            id => my_throttled_events_drop
          }
        }

```

```auto
    output {
      if "throttled_metrics" in [tags] {
        graphite {
          host => "${GRAPHITE_HOST}"
          port => "${GRAPHITE_PORT}"
          fields_are_metrics => true
        }
      } else {
        elasticsearch {
          user => logstash_internal
          password => "${LOGSTASH_PASS}"
          ssl => true
          cacert => '/usr/share/logstash/config/ca_cert.pem'
          hosts => ["${ELASTICSEARCH_HOST}:${ELASTICSEARCH_PORT}"]
          manage_template => false
          index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
        }
      }
    }  

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2021, 4:44pm UTC](https://discuss.elastic.co/t/metric-and-drop-filter-not-working-together/286380/2 "2021-10-11T16:44:13Z")

</div>

> [@Rakesh\_Partapsing](#):
>
> `if "throttled_events" in [tags] {`

In this code block you have a metrics filter that creates events, followed by a drop filter that unconditionally deletes them. You need another conditional around the drop filter that only matches the events you want dropped.

---

<div class="post-metadata">

**Author:** ![Rakesh\_Partapsing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_partapsing/32/95701_2.png) [@Rakesh\_Partapsing](https://discuss.elastic.co/u/Rakesh_Partapsing)\
**Post date:** [October 12, 2021, 12:07pm UTC](https://discuss.elastic.co/t/metric-and-drop-filter-not-working-together/286380/3 "2021-10-12T12:07:05Z")

</div>

awesome that works. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 12:07pm UTC](https://discuss.elastic.co/t/metric-and-drop-filter-not-working-together/286380/4 "2021-11-09T12:07:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
