# Wanted to drop specific syslog message and syslog Client

**URL:** <https://discuss.elastic.co/t/wanted-to-drop-specific-syslog-message-and-syslog-client/305498>\
**Category:** Kibana\
**Created:** [May 24, 2022, 11:56am UTC](https://discuss.elastic.co/t/wanted-to-drop-specific-syslog-message-and-syslog-client/305498 "2022-05-24T11:56:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashisharyan](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@ashisharyan](https://discuss.elastic.co/u/ashisharyan)\
**Post date:** [May 24, 2022, 11:56am UTC](https://discuss.elastic.co/t/wanted-to-drop-specific-syslog-message-and-syslog-client/305498/1 "2022-05-24T11:56:07Z")

</div>

Hi,

I wanted to drop some specific syslog message and syslog client which should not be send to ELK. Below is the Logstash config file. we have tried but it is not working.  
So request if anyone can help me to get this work.

```auto
input {
    beats {
        port => "5044"
    }
}
filter {
    grok {
        match => { "message" => "%{SYSLOGLINE}"}
      }
    if ([message] !~ "Test Message") {
    drop { }
    }
}
output {
    elasticsearch {
        hosts => ["192.168.0.105:9200"]
    }
}

```

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2022, 11:56am UTC](https://discuss.elastic.co/t/wanted-to-drop-specific-syslog-message-and-syslog-client/305498/2 "2022-06-21T11:56:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
