# Prevent some logs from going to the elastic search

**URL:** <https://discuss.elastic.co/t/prevent-some-logs-from-going-to-the-elastic-search/11969>\
**Category:** Elasticsearch\
**Created:** [May 15, 2013, 8:08am UTC](https://discuss.elastic.co/t/prevent-some-logs-from-going-to-the-elastic-search/11969 "2013-05-15T08:08:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aakashanuj](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@aakashanuj](https://discuss.elastic.co/u/aakashanuj)\
**Post date:** [May 15, 2013, 8:08am UTC](https://discuss.elastic.co/t/prevent-some-logs-from-going-to-the-elastic-search/11969/1 "2013-05-15T08:08:52Z")

</div>

I am using Logstash to send logs to the Elastic search. Now I want only the  
logs with a particular regex to go to the elastic search and I want the  
others to be dropped.

How do I achieve it?

My configuration file is:

input {  
file  
{  
path =\> "/home/aakash/Desktop/aa.txt"  
type =\> "filetype"  
debug=\> "true"  
}  
}  
filter {

grok {  
type =\> "filetype"  
patterns\_dir=\>["./patterns"]  
pattern =\> "%{PARSE\_ERROR}|%{OTHERS}"  
add\_tag=\>"%{type1},%{type2},%{slave},ERR\_SYSTEM,%{fiber1},%{fiber2}"  
}

mutate  
{  
type=\>"filetype"  
replace =\> ["@message", "%{message}"]  
replace =\>["@timestamp","%{year}-%{monthnum}-%{monthday}T%{hour}:  
%{minute}:%{second}.%{\_second}Z"]  
}

}  
output {  
stdout { debug =\> true debug\_format =\> "json"}  
elasticsearch  
{  
}  
}

I want the %{OTHERS } to be dropped. How do I modify this code?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [May 15, 2013, 3:56pm UTC](https://discuss.elastic.co/t/prevent-some-logs-from-going-to-the-elastic-search/11969/2 "2013-05-15T15:56:08Z")

</div>

This sounds like a question for the Logstash community, not the  
Elasticsearch mailing list.

--  
Ivan

On Wed, May 15, 2013 at 1:08 AM, Aakash Anuj [aakashanuj.iitkgp@gmail.com](mailto:aakashanuj.iitkgp@gmail.com)wrote:

> I am using Logstash to send logs to the Elastic search. Now I want only  
> the logs with a particular regex to go to the Elasticsearch and I want the  
> others to be dropped.
> 
> How do I achieve it?
> 
> My configuration file is:
> 
> input {  
> file  
> {  
> path =\> "/home/aakash/Desktop/aa.txt"  
> type =\> "filetype"  
> debug=\> "true"  
> }  
> }  
> filter {
> 
> grok {  
> type =\> "filetype"  
> patterns\_dir=\>["./patterns"]  
> pattern =\> "%{PARSE\_ERROR}|%{OTHERS}"  
> add\_tag=\>"%{type1},%{type2},%{ **slave},ERR\_SYSTEM,%{fiber1},%{**  
> fiber2}"  
> }
> 
> mutate  
> {  
> type=\>"filetype"  
> replace =\> ["@message", "%{message}"]  
> replace =\>["@timestamp","%{year}-%{ **monthnum}-%{monthday}T%{hour}:**  
> %{minute}:%{second}.%{\_second}\*\*Z"]  
> }
> 
> }  
> output {  
> stdout { debug =\> true debug\_format =\> "json"}  
> elasticsearch  
> {  
> }  
> }
> 
> I want the %{OTHERS } to be dropped. How do I modify this code?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:36am UTC](https://discuss.elastic.co/t/prevent-some-logs-from-going-to-the-elastic-search/11969/3 "2017-07-06T02:36:28Z")

</div>


