# Skip indexing based on field value

**URL:** <https://discuss.elastic.co/t/skip-indexing-based-on-field-value/107280>\
**Category:** Elasticsearch\
**Created:** [November 11, 2017, 5:49pm UTC](https://discuss.elastic.co/t/skip-indexing-based-on-field-value/107280 "2017-11-11T17:49:42Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 11, 2017, 6:09pm UTC](https://discuss.elastic.co/t/skip-indexing-based-on-field-value/107280/2 "2017-11-11T18:09:48Z")

</div>

That's something you need to fix in the ingest layer.

If you are using logstash, it's easy to call the drop filter.

@magnusbaeck wrote a nice example here:

> [@Creating drop filters based on a string search in a message field](https://discuss.elastic.co/t/creating-drop-filters-based-on-a-string-search-in-a-message-field/64050/7):
>
> There's nothing wrong with the filter. Perhaps you're not running with the configuration you expect? $ cat test.config input { stdin { } } output { stdout { codec =\> rubydebug } } filter { if "ASA-6-302013" in [message] { drop{ } } } $ ( echo 'first message' ; echo 'Oct 27 12:43:28 asa10 : %ASA-6-302013: Built inbound TCP connection 1033541997 for outside:10.150.0.0./46742 (10.150.0.0/46742) to inside.customer:172.26.0.0/8080 (161.215.0.0/8080)' ; echo 'third message' ) | /opt/logstash/bin/l…

---

_[View the full topic](https://discuss.elastic.co/t/skip-indexing-based-on-field-value/107280)._
