# Configure Beats to only see certain fields in Elasticsearch

**URL:** <https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161>\
**Category:** Beats\
**Tags:** filebeat, packetbeat, winlogbeat\
**Created:** [February 3, 2022, 9:17am UTC](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161 "2022-02-03T09:17:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [February 3, 2022, 9:17am UTC](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161/1 "2022-02-03T09:17:44Z")

</div>

Hi Guys,  
first of all, I do apologize if this is something that had been answered in the past.

What I'm trying to achieve is the following - let's take the Winlogbeat as an example:  
I'm only interested to see what type of Events have been triggered, as well as the Hostname who has triggered this, the Username, potentially the Message of this Event, ProcessName(s), Event-ID(s), Host-Ip plus Host-Mac and the Timestamp, when the Event was triggered.

If I however start to add the Event-IDs I'm interested in - using the below lines - I do also get informations such as Host-Plattform, OS-Type etc etc (so all of the stuff I don't want to see).

```auto
winlogbeat.event_logs:
  # - name: System
  - name: Security
    event_id: 4624, 4625, 4656, 4670, 4672, 4688

```

Is there any way of basically configuring the output to only show those bits mentioned above? If so, how and where do i do this? Is it in the Logstash config file where I have to add this?

Sorry for those questions - I'm still a newby and I haven't found an answer to this here - I might have not searched properly.

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [February 3, 2022, 9:45am UTC](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161/2 "2022-02-03T09:45:22Z")

</div>

hi @_Thomas , you can use the `drop_fields` processor to drop specific fields, more on this here [Drop fields from events | Winlogbeat Reference [master] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/master/drop-fields.html)

---

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [February 3, 2022, 9:55am UTC](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161/3 "2022-02-03T09:55:18Z")

</div>

@MarianaD ohhh that's awesome - thank you.

I assume this is the correct way of using this option:

```auto
processors:
    - drop_fields:
      when:
        has_fields:
      fields: ["agent.ephemeral_id", "agent.hostname", ...]
      ignore_missing: false

```

EDIT:  
Am I not allowed to write the drop\_fields like this:

```auto
processors:
  #- add_host_metadata:
      #when.not.contains.tags: forwarded
  #- add_cloud_metadata: ~
    - drop_fields:
when:
        has_fields:
      fields: ['agent.ephemeral_id', 'agent.id', 'agent.name', 'agent.type', 'agent.version', 'ecs.version', 'event.action', 'event.code', 'event.kind', 'event.outcome', 'event.provider', 'host.architecture', 'host.id', 'host.name', 'host.os.build', 'host.os.family', 'host.os.kernel', 'host.os.name', 'host.os.platform', 'host.os.type', 'host.os.version', 'log.level', 'winlog.activity_id', 'winlog.api', 'winlog.channel', 'winlog.computer_name', 'winlog.event_data.AuthenticationPackageName', 'winlog.event_data.ElevatedToken', 'winlog.event_data.ImpersonationLevel', 'winlog.event_data.IpAddress', 'winlog.event_data.IpPort', 'winlog.event_data.IpKeyLength', 'winlog.event_data.LmPackageName', 'winlog.event_data.LogonGUID', 'winlog.event_data.LogonProcessName', 'winlog.event_data.LogonType', 'winlog.event_data.ProcessId', 'winlog.event_data.RestrictedAdminMode', 'winlog.event_data.SubjectDomainName', 'winlog.event_data.SubjectLogonId', 'winlog.event_data.SubjectUserName', 'winlog.event_data.SubjectUserSid', 'winlog.event_data.TargetDomainName', 'winlog.event_data.TargetLinkedLogonId', 'winlog.event_data.TargetOutboundDomainName', 'winlog.event_data.TargetOutboundUserName', 'winlog.event_data.TargetUserName', 'winlog.event_data.TargetUserSid', 'winlog.event_data.TransmittedServices', 'winlog.event_data.VirtualAccount', 'winlog.opcode', 'winlog.process.threat.id', 'winlog.provider_guid', 'winlog.provider_name', 'winlog.task', 'winlog.version']
      ignore_missing: false

```

Because I get this Error Message:  
Exiting: error loading config file: yaml: line 131: did not find expected key

Line 131 is basically where the "has\_fields" command starts

EDIT 2:  
Exiting: error initializing processors: each processor must have exactly one action, but found 3 actions (fields,ignore\_missing,drop\_fields)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2022, 11:55am UTC](https://discuss.elastic.co/t/configure-beats-to-only-see-certain-fields-in-elasticsearch/296161/4 "2022-03-03T11:55:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
