# Automatically excluding fields in new indexes

**URL:** <https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641>\
**Category:** Elasticsearch\
**Created:** [October 16, 2018, 11:25am UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641 "2018-10-16T11:25:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![braoul](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@braoul](https://discuss.elastic.co/u/braoul)\
**Post date:** [October 16, 2018, 11:25am UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/1 "2018-10-16T11:25:53Z")

</div>

Hi,

we have setup different indexes by day on our data and now we would like to exclude some fields from being indexed.  
How should we proceed, so that every newly created index will automatically have those fields excluded ?

Thank you,  
Boris

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 16, 2018, 11:37am UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/2 "2018-10-16T11:37:52Z")

</div>

Hey Braoul,

It depends a bit how you ingest the data to decide what your options are. Are you using Beats agents to ingest the data? Do you ingest data into Elasticsearch directly or do you ingest the data into Logstash?

When using Beats, you could the `drop_fields` processor, for example:

```
  - drop_fields:
      fields: ["kubernetes.pod.start_time"]
      when.equals:
        kubernetes.pod.start_time: ""

```

[https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html)

When not using Beats, you could make use of an Elasticsearch remove processor:

[https://www.elastic.co/guide/en/elasticsearch/reference/current/remove-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/remove-processor.html)

When you use Logstash, you can create a remove\_field mutate filter:

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-remove\_field](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-remove_field)

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![braoul](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@braoul](https://discuss.elastic.co/u/braoul)\
**Post date:** [October 16, 2018, 12:01pm UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/3 "2018-10-16T12:01:17Z")

</div>

Thank you Willem.

I am using Logstash, and I am already using blacklists or whitelists to filter some data.

What I would like to do is to store the fields, to be able to see them when needed, but not indexing them, to decrease the processing power needed. For that I thought about putting "index" : "no" in the index definition.  
Is what I would like actually possible? or do I have to remove the fields in Logstash like you propose to decrease the cpu needed?

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 16, 2018, 12:16pm UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/4 "2018-10-16T12:16:25Z")

</div>

Braoul,

You can use the `"enabled": false` mapping parameter in your template for that I think:

[https://www.elastic.co/guide/en/elasticsearch/reference/current/enabled.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/enabled.html)

Let me know if that works for you, I never used that actually.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![braoul](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@braoul](https://discuss.elastic.co/u/braoul)\
**Post date:** [October 16, 2018, 1:26pm UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/5 "2018-10-16T13:26:40Z")

</div>

Thank you very much! it seems like what I mean.

Now, do you know if it is possible to apply "enabled":false to the new indexes that will be created everyday?

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 16, 2018, 3:47pm UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/6 "2018-10-16T15:47:18Z")

</div>

> [@willemdh](#):
>
> You can use the `"enabled": false` mapping parameter in your template

As I said, you can define this in the template for your index. Template settings get applied to the corresponding indices the moment they are created.

> **[Index templates | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)**

---

<div class="post-metadata">

**Author:** ![braoul](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@braoul](https://discuss.elastic.co/u/braoul)\
**Post date:** [October 17, 2018, 7:06am UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/7 "2018-10-17T07:06:58Z")

</div>

Ok great, I was not aware of the index templates in Kibana. Thank you for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2018, 7:07am UTC](https://discuss.elastic.co/t/automatically-excluding-fields-in-new-indexes/152641/8 "2018-11-14T07:07:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
