# Pass multiple conditions as an array to drop\_event

**URL:** <https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 29, 2020, 3:23am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502 "2020-02-29T03:23:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![jibsonline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jibsonline/32/63154_2.png) [@jibsonline](https://discuss.elastic.co/u/jibsonline)\
**Post date:** [February 29, 2020, 3:23am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/1 "2020-02-29T03:23:32Z")

</div>

Hi,

I am trying to pass multiple values as an array to `drop_event`

This works

```
      processors:
      - drop_event:
          when:
             contains:
                message: "Starting Session"

```

But I have multiple strings to match

The both below doesn't

```
      processors:
      - drop_event:
          when:
             contains:
                message: ["Starting Session","Started Session","Removed slice User"]

```

* * *

```
          processors:
          - drop_event:
              when:
                 contains:
                    message:
                      - "Starting Session"
                      - "Started Session"
                      - "Removed slice User"

```

What am I doing wrong here?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [March 3, 2020, 7:30pm UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/2 "2020-03-03T19:30:35Z")

</div>

Hey @jibsonline,

I am not sure if `contains` supports multiple values in the same condition, you would need to define multiple `contains` conditions joined by an `or` condition, something like this:

```auto
          processors:
          - drop_event:
              when:
                 or:
                   - contains.message: "Starting Session"
                   - contains.message: "Started Session"
                   - contains.message: "Removed slice User"

```

Or you may try to build a condition using a single regular expression, something like this:

```auto
          processors:
          - drop_event:
              when:
                 regexp:
                   message: "(Starting Session|Started Session|Removed slice User)"

```

---

<div class="post-metadata">

**Author:** ![jibsonline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jibsonline/32/63154_2.png) [@jibsonline](https://discuss.elastic.co/u/jibsonline)\
**Post date:** [March 4, 2020, 12:21am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/3 "2020-03-04T00:21:19Z")

</div>

Thanks. So what does this do

`message: ["Starting Session","Started Session","Removed slice User"]`

As mentioned in the documentation

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [March 4, 2020, 11:29am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/4 "2020-03-04T11:29:16Z")

</div>

Where is this mentioned in the documentation? I think that only some conditions support something like this.

---

<div class="post-metadata">

**Author:** ![jibsonline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jibsonline/32/63154_2.png) [@jibsonline](https://discuss.elastic.co/u/jibsonline)\
**Post date:** [March 4, 2020, 11:04pm UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/5 "2020-03-04T23:04:03Z")

</div>

> [@jsoriano](#):
>
> Where is this mentioned in the documentation?

> **[Define processors | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-contains)**

> **contains**  
> The contains condition checks if a value is part of a field. The field can be a string or an array of strings. The condition accepts only a string value.

But it doesn't say what condition is satisfied when "an array of strings" are passed. People tend to assume it will match on "any"

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [March 5, 2020, 10:18am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/6 "2020-03-05T10:18:30Z")

</div>

Oh, this means that the field in the document can be a string or an array of strings, in that case the condition matches if any of these strings matches.  
But the documentation also mentions that _"The condition accepts only a string value"_.

---

<div class="post-metadata">

**Author:** ![jibsonline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jibsonline/32/63154_2.png) [@jibsonline](https://discuss.elastic.co/u/jibsonline)\
**Post date:** [March 5, 2020, 11:30am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/7 "2020-03-05T11:30:55Z")

</div>

But the condition doesn't trigger when any of the strings matches. You can refer to my initial post

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [March 5, 2020, 11:45am UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/8 "2020-03-05T11:45:16Z")

</div>

> [@jibsonline](#):
>
> But the condition doesn't trigger when any of the strings matches. You can refer to my initial post

In your initial post you are passing arrays of strings to the condition, but as documentation says, _"The condition accepts only a string value"_.

When the documentation says that the field can be an array of strings, it means that if you have field in a document that is an array of strings, like `tags` int this one:

```auto
{
  "tags": [
    "session",
    "start"
  ]
}

```

And a condition like this one:

```auto
      processors:
      - drop_event:
          when:
             contains:
                tags: "session"

```

The condition will match.

Let me know if this helps to clarify. I see that mentioning that the field can be an array of strings can be confusing, but I think the docs are clear about not accepting arrays in the condition.

---

<div class="post-metadata">

**Author:** ![jibsonline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jibsonline/32/63154_2.png) [@jibsonline](https://discuss.elastic.co/u/jibsonline)\
**Post date:** [March 5, 2020, 4:50pm UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/9 "2020-03-05T16:50:06Z")

</div>

Got it. I missed "The field" part of it. Misinterpreted it as "The condition" can can be a string or array.

But still it should throw an error when an unacceptable mapping is found for the condition because it says " _"The condition accepts only a string value"_ .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2020, 4:50pm UTC](https://discuss.elastic.co/t/pass-multiple-conditions-as-an-array-to-drop-event/221502/10 "2020-04-02T16:50:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
