# Use logcheck ignore rules

**URL:** <https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149>\
**Category:** Logstash\
**Created:** [May 27, 2016, 10:39am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149 "2016-05-27T10:39:50Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![quimnuss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quimnuss/32/9992_2.png) [@quimnuss](https://discuss.elastic.co/u/quimnuss)\
**Post date:** [May 27, 2016, 10:39am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/1 "2016-05-27T10:39:50Z")

</div>

I've started using ELK yesterday, moving from logcheck and I would like to re-use the ignore rules of logcheck and some custom I had added. I currently have two servers providing logs throught filebeat to logstash, who then passes them on to elasticsearch and kibana.

I see two ways of doing this, either by filtering the logs before giving them to elasticsearch (or kibana?\*) or by somehow enable a data view of some sort which doesn't include the ignored lines on searches and so on.

I've seen that logstash has grep filters, could you point me to a good tutorial on how to use it? And maybe give your 5 cents on the proper way to do this.

What would you recommend?

\*I am a newbie here, I am still illiterate about who is supposed to do what, not to say the proper terminology.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 29, 2016, 10:43am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/2 "2016-05-29T10:43:10Z")

</div>

The grep filter was deprecated years ago. This is how you'd typically drop boring events:

```nohighlight
filter {
  if [message] =~ /regexp matching event I don't care about/ {
    drop { }
  }
}

```

---

<div class="post-metadata">

**Author:** ![quimnuss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quimnuss/32/9992_2.png) [@quimnuss](https://discuss.elastic.co/u/quimnuss)\
**Post date:** [May 30, 2016, 8:32am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/3 "2016-05-30T08:32:48Z")

</div>

Excellent!

What about reading the regexp from a file or files? I could generate such  
filter with a script but that would make a huge 'if' containing all  
logcheck's drop rules.

Cheers,

Pol

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 30, 2016, 8:39am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/4 "2016-05-30T08:39:51Z")

</div>

You might be able to use the translate filter, but otherwise generating a configuration file is probably your best bet. Keep in mind that this can significantly affect the event throughput.

---

<div class="post-metadata">

**Author:** ![quimnuss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quimnuss/32/9992_2.png) [@quimnuss](https://discuss.elastic.co/u/quimnuss)\
**Post date:** [May 30, 2016, 9:20am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/5 "2016-05-30T09:20:38Z")

</div>

Thanks Magnus for the prompt reply.

Could you elaborate on what do you mean as for configuration file? Are you  
referring to pre-filter syslog somehow before sending it via filebeat or  
the drop filter you mentioned on your first post?

I was indeed pointing at the performance impact filtering in that way might  
have on my previous comment. I don't know if it would be of concern.

Cheers,

Pol

ps.  
As a side quest, I think I am more inclined now to publish all logs but  
have a default view on the stored data with the boring messages filtered  
out, but being able to switch the filter off to see a suspicious log  
message in context.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 30, 2016, 1:45pm UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/6 "2016-05-30T13:45:06Z")

</div>

> Could you elaborate on what do you mean as for configuration file? Are you  
> referring to pre-filter syslog somehow before sending it via filebeat or  
> the drop filter you mentioned on your first post?

Whichever works best, really.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/use-logcheck-ignore-rules/51149/7 "2017-07-06T04:55:29Z")

</div>


