# Nginx module | Processor drop\_event HTTP 200 not working

**URL:** <https://discuss.elastic.co/t/nginx-module-processor-drop-event-http-200-not-working/203352>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 13, 2019, 4:42pm UTC](https://discuss.elastic.co/t/nginx-module-processor-drop-event-http-200-not-working/203352 "2019-10-13T16:42:26Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 14, 2019, 1:41am UTC](https://discuss.elastic.co/t/nginx-module-processor-drop-event-http-200-not-working/203352/3 "2019-10-14T01:41:26Z")

</div>

Ahh take a look at [this](https://discuss.elastic.co/t/filebeat-nginx-module-not-dropping-events/160797/4) post. Now it makes more sense.

For Filebeat the whole log line gets shipped as the `message` and then processed with the ingest Pipeline on the Elasticsearch side so the fields are not available yet for the `drop_event` processor on the harvestor side so it can not find the field and thus is not executed and that is probably what is producing those error logs.

You will need to use a different approach.

Example `exclude_line` or a `drop_event` with regex on the `message` field etc

NOTE I got this to work in the `nginx.yml`

```
- module: nginx

  # Access logs
  access:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/Users/sbrown/workspace/sample-data/nginx/nginx.log"]

    input:
      processors:
      - add_locale: ~
      - drop_event.when.regexp.message: " 200 "

```

BTW I had the add the `add_locale` as it seems it is added automatically but needs to be explicitly defined when adding another processors perhaps that is a minor bug.

---

_[View the full topic](https://discuss.elastic.co/t/nginx-module-processor-drop-event-http-200-not-working/203352)._
