elastic / elastic/docs-content

[Website]: Misleading Usage of common options within Logstash drop filter documentation

Open
#1,753 0 comments 0 reactions 0 assignees View on GitHub
source:web Team:Ingest
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Type of issue

Inaccurate

### What documentation page is affected

https://www.elastic.co/docs/reference/logstash/plugins/plugins-filters-drop

### What happened?

The drop filter plugin documentation includes a section listing common options, such as `add_field` or `drop_field`, which do not have the expected effect because the entire event is dropped. Specifically, the inclusion of the `drop_field` option can mislead users into thinking that only a specific field will be dropped, rather than the entire event. Since the drop filter removes everything that reaches it, any `drop_field` specified will not isolate the removal to just that field.

### Additional info

Instead of using `drop_field` within the drop filter, it should instead be used within the [mutate filter](https://www.elastic.co/docs/reference/logstash/plugins/plugins-filters-mutate#plugins-filters-mutate-remove_field).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.