# Cannot remove "Type" field added with Logstash

**URL:** <https://discuss.elastic.co/t/cannot-remove-type-field-added-with-logstash/171053>\
**Category:** Logstash\
**Created:** [March 6, 2019, 8:31am UTC](https://discuss.elastic.co/t/cannot-remove-type-field-added-with-logstash/171053 "2019-03-06T08:31:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![a.sailor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a.sailor/32/38567_2.png) [@a.sailor](https://discuss.elastic.co/u/a.sailor)\
**Post date:** [March 6, 2019, 8:31am UTC](https://discuss.elastic.co/t/cannot-remove-type-field-added-with-logstash/171053/1 "2019-03-06T08:31:52Z")

</div>

Hello ELK gurus,  
i'm completing my company's cluster configuration but now i have one big issue.

I have grok patterns configured like this:

```
grok {
  #portal.redirector-access
   match => { "message" => "%{DATA:faceserver} %{DATA:portal}: %{DATA:app_portal} %{IP:ip} - - - %{NUMBER:response} %{GREEDYDATA:request} %{NUMBER:ask1} \"%{GREEDYDATA:url}\"" }
   add_field => {
   "type" => "portal.redirector-access"
    }
}

```

Even if i remove the "add\_field" lines, i still have logs coming in ES with type attached.  
I also tried:

```
mutate {
   remove_field => ["type"]
}

```

... but doesn't work either.  
Any suggestions ? Am i missing something ?

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2019, 8:31am UTC](https://discuss.elastic.co/t/cannot-remove-type-field-added-with-logstash/171053/2 "2019-04-03T08:31:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
