> For the complete documentation index, see [llms.txt](https://omalab.gitbook.io/guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://omalab.gitbook.io/guide/engineering-wiki/monitoring-and-alerting/updating-kibana-filtering.md).

# Updating Kibana Filtering

## Updating the filters

1. On Bastion host which works as a ELK server, log in and become root.
2. `cd /etc/logstash/conf.d/`

   and edit file:

   `vi 899-filter-unneeded.conf`
3. Add the needed filter at the end just before the last } if \[message] =\~ "after\_perform" {

   drop { }\` }
4. Restart logstash:

   `service logstash restart`

## Notes

The simpler the better, this burns a lot of CPU.
