# Simple Filter - Multiple OR

**URL:** <https://discuss.elastic.co/t/simple-filter-multiple-or/104295>\
**Category:** Logstash\
**Created:** [October 17, 2017, 6:56pm UTC](https://discuss.elastic.co/t/simple-filter-multiple-or/104295 "2017-10-17T18:56:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jameswatson3](https://avatars.discourse-cdn.com/v4/letter/j/a6a055/32.png) [@jameswatson3](https://discuss.elastic.co/u/jameswatson3)\
**Post date:** [October 17, 2017, 6:56pm UTC](https://discuss.elastic.co/t/simple-filter-multiple-or/104295/1 "2017-10-17T18:56:08Z")

</div>

I have a working filter that is meeting my needs but I'm wondering about the efficiency as it grows. My apologies for the formatting as I'm inexperienced on this forum but my filter is as follows:

filter {  
if [type] == "wineventlog" {  
if [message] =~ 'CONHOST.EXE' or  
[message] =~ 'UPDATETRUSTEDSITES.EXE' or  
[message] =~ 'DLLHOST.EXE' or  
[message] =~ 'CHROME.EXE' or  
[message] =~ 'TASKHOSTW.EXE' or  
[message] =~ 'OFFICEBACKGROUNDTASKHANDLER.EXE' or  
[message] =~ 'ACRODIST.EXE' {  
drop { }  
}  
}  
}

What I'm trying to accomplish is capture AppLocker events from 10's of 1000's of student computers for security purposes and there is no need to log expected OS/application behavior. I can see needing to add many more [message] =~ lines in the future but I'm concerned that I may be inefficiently re-reading the same message field again and again possibly causing performance issues.

Any suggestions on a recommended way to do this? Or is this already optimized by logstash?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 17, 2017, 7:04pm UTC](https://discuss.elastic.co/t/simple-filter-multiple-or/104295/2 "2017-10-17T19:04:08Z")

</div>

I suggest you extract the filename to a field of its own (e.g. using a grok filter) and use a translate filter to look up the executable name against a table of known good programs. The translate filter can set a field value or a tag if the executable was found in the list and then you can use a conditional to check against that value and drop the event.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2017, 7:04pm UTC](https://discuss.elastic.co/t/simple-filter-multiple-or/104295/3 "2017-11-14T19:04:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
