# Cannot remove "host" field

**URL:** <https://discuss.elastic.co/t/cannot-remove-host-field/141232>\
**Category:** Logstash\
**Created:** [July 23, 2018, 5:43pm UTC](https://discuss.elastic.co/t/cannot-remove-host-field/141232 "2018-07-23T17:43:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![MartinCorrado](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@MartinCorrado](https://discuss.elastic.co/u/MartinCorrado)\
**Post date:** [July 23, 2018, 5:43pm UTC](https://discuss.elastic.co/t/cannot-remove-host-field/141232/1 "2018-07-23T17:43:07Z")

</div>

Hi! I'm trying to remove the "host" field but it seems that it's not working for me and every time I recreate the logstash instance, the second time that my queries are executed the following error appears over and over again:

\_[2018-07-23T17:34:57,917][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"dev-infor-2018.07.23", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x588ca1c3], :response=\>{"index"=\>{"\_index"=\>"dev-infor-2018.07.23", "\_type"=\>"doc", "_id"=\>"New1yGQBFDLybt\_JXRh1", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [host] tried to parse field [host] as object, but found a concrete value"}}}}_

My pipeline is:

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* \* \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/engage-register-count.sql"  
clean\_run =\> true  
tags =\> ["engage-register-count"]  
add\_field =\> { "query\_type" =\> "registercount" }  
}  
}

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* 9,15,21 \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/orphaned-item.sql"  
clean\_run =\> true  
tags =\> ["orphaned-items"]  
add\_field =\> { "query\_type" =\> "orphaned" }  
}  
}

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* \* \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/engage-store-transaction-time.sql"  
clean\_run =\> true  
tags =\> ["engage-store-transaction-time"]  
add\_field =\> { "query\_type" =\> "store-transaction-time" }  
}  
}

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* \* \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/engage-transaction-offline-amount.sql"  
clean\_run =\> true  
tags =\> ["engage-transaction-offline-amount"]  
add\_field =\> { "query\_type" =\> "register-saf-amount" }  
}  
}

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* \* \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/engage-store-business-type.sql"  
clean\_run =\> true  
tags =\> ["engage-store-business-type"]  
add\_field =\> { "query\_type" =\> "store-type" }  
}  
}

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* \* \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/engage-saf-validation.sql"  
clean\_run =\> true  
tags =\> ["engage-saf-validation"]  
add\_field =\> { "query\_type" =\> "saf-status-count" }  
}  
}

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/postgresql-{{ pg\_jdbc\_version }}.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
jdbc\_connection\_string =\> "jdbc:postgresql://{{ postgres\_host }}:5432/arts\_v6"  
jdbc\_user =\> "postgres"  
jdbc\_password =\> "postgres"  
schedule =\> "\* \* \* \* \*"  
statement\_filepath =\> "/etc/logstash/pipelines/engage-store-transaction-time-histogram.sql"  
clean\_run =\> true  
tags =\> ["engage-store-transaction-time-histogram"]  
add\_field =\> { "query\_type" =\> "txn-time-history" }  
}  
}

filter {  
mutate {  
add\_field =\> {"infor\_stack\_name" =\> "{{ env }}-{{ customer\_code }}" }  
add\_field =\> {"infor\_stack\_version" =\> "{{ product\_version }}" }  
remove\_field =\> ["host"]  
}

if "engage-register-count" in [tags] {  
mutate {  
convert =\> {"registercount" =\> "integer" }  
add\_field =\> {"resultId" =\> "%{query\_type}" }  
}  
}

if "engage-store-transaction-time" in [tags] {  
mutate {  
convert =\> {"percentile\_50" =\> "float" }  
convert =\> {"percentile\_95" =\> "float" }  
convert =\> {"percentile\_99" =\> "float" }  
add\_field =\> {"resultId" =\> "%{query\_type}-%{storeid}" }  
}  
}

if "engage-transaction-offline-amount" in [tags] {  
mutate {  
add\_field =\> {"resultId" =\> "%{query\_type}-%{storeid}-%{workstationId}" }  
}  
}

if "engage-store-business-type" in [tags] {  
mutate {  
add\_field =\> {"resultId" =\> "%{query\_type}-%{storeid}" }  
}  
}

if "engage-saf-validation" in [tags] {  
mutate {  
add\_field =\> {"resultId" =\> "%{query\_type}" }  
}  
}

if "engage-store-transaction-time-histogram" in [tags] {  
mutate {  
convert =\> {"averageTimeSeconds" =\> "float" }  
add\_field =\> {"resultId" =\> "%{query\_type}-%{storeid}-%{+YYYY.MM.dd.HH.mm.ss.SSS}" }  
}  
}

}

output {

if "orphaned-items" not in [tags] {  
elasticsearch {  
hosts =\> "{{ external\_elk\_url }}"  
user =\> "{{ external\_elk\_user }}"  
password =\> "{{ external\_elk\_pass }}"  
index =\> "engage-jdbc-{{ env}}-{{ customer\_code }}-%{+YYYY.MM.dd}"  
document\_id =\> "engage-jdbc-%{resultId}"  
}  
}

{% if use\_kinesis is defined and use\_kinesis == "Enabled" %}  
if "orphaned-items" in [tags] {  
kinesis {  
stream\_name =\> "{{ env }}-{{ customer\_code }}-base-RetailerLogStream"  
region =\> "{{ region }}"  
}  
}  
{% endif %}

}

Have no clue why is not working, since _remove\_field =\> ["host"]_ should be enough.

Any ideas?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 25, 2018, 8:13pm UTC](https://discuss.elastic.co/t/cannot-remove-host-field/141232/2 "2018-07-25T20:13:38Z")

</div>

Are you really running the configuration you think you're running? According to the log Logstash is trying to send the events to the dev-infor-2018.07.23 index but there's no elasticsearch output in your configuration that matches that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2018, 8:16pm UTC](https://discuss.elastic.co/t/cannot-remove-host-field/141232/3 "2018-08-22T20:16:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
