[Resolved] Grok filter discard entities


#1

How can I exclude / discard those events which the grok filter fails to parse? I would like to just discard such events instead of crashing the service.


(Mark Walkom) #2

They shouldn't crash the service, if they are then there are other problems.

However this should work;

if "_grokparsefailure" in [tags] {
  drop { }
}

#3

Thanks @warkolm. This is what I was looking for.


(system) #4