# Delete a field in filter, but use it in output

**URL:** <https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008>\
**Category:** Logstash\
**Created:** [April 21, 2016, 9:08am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008 "2016-04-21T09:08:46Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![JvonRudno](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Post date:** [April 21, 2016, 9:08am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/1 "2016-04-21T09:08:46Z")

</div>

Hi everybody,

I am using:  
input {  
jdbc {  
}  
}

filter {  
elasticsearch {  
remove\_field =\> ["index\_type"]  
}  
}

output {  
elasticsearch{  
index =\> "myindex"  
document\_type =\> "%{index\_type}"  
document\_id =\> "%{customerno}"  
}  
}  
I have a field in the input that has the name of the document\_type, but I don't want that this field come in the document. If I use the filter to delete the field "index\_type" I can not use it in the output to setting the document\_type.

In resum I don't want the field in the domucument\_source but I need it to configure the document\_type

How I can do this?

Thanks a lot for your help!!

Regards.

Jorge von Rudno

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 21, 2016, 9:13am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/2 "2016-04-21T09:13:23Z")

</div>

You can copy the field into [event metadata](https://www.elastic.co/blog/logstash-metadata) prior to removing it, which will allow you to use it in outputs without having it in the document itself.

---

<div class="post-metadata">

**Author:** ![JvonRudno](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Post date:** [April 21, 2016, 9:28am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/3 "2016-04-21T09:28:15Z")

</div>

Thanks a lot Chirstian, I will do this!!!

Regards

Jorge

---

<div class="post-metadata">

**Author:** ![JvonRudno](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Post date:** [April 21, 2016, 10:15am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/4 "2016-04-21T10:15:09Z")

</div>

Hi Christian,

Please what have I wrong in this configuration. I get an error:

---

<div class="post-metadata">

**Author:** ![JvonRudno](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Post date:** [April 21, 2016, 10:16am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/5 "2016-04-21T10:16:44Z")

</div>

Sorry I send without complete:

Error: Expected one of #, =\> at line 18, column 9 (byte 531) after filter {  
elasticsearch {  
"[@metadata][index\_type]"  
{:level=\>:error}

The config file is this:

filter {  
elasticsearch {  
"[@metadata][index\_type]"  
remove\_field =\> ["index\_type"]  
}  
}

output {  
elasticsearch{  
index =\> "myindex"

# document\_type =\> "%{index\_type}"

```
document_type => "%{[@metadata][index_type]}" 
document_id => "%{customerno}"

```

}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 21, 2016, 1:50pm UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/6 "2016-04-21T13:50:24Z")

</div>

Why are you using the elasticsearch filter to modify fields? Even though it may be possible to use it as it inherits the base operations, the [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html) is generally the natural choice for altering the structure of your event. First use add\_field to copy the data to the metadata field and then remove the field you no longer want in your event. In order to guarantee that one step is done before the other I believe you will need to specify 2 mutate blocks. Something like this:

```
{
    mutate { add_field => { "[@metadata][index_type]" => "%{index_type}" } }
    mutate { remove_field => ["index_type"] }
}
```

---

<div class="post-metadata">

**Author:** ![JvonRudno](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Post date:** [April 21, 2016, 1:53pm UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/7 "2016-04-21T13:53:13Z")

</div>

Hi Christian thanks a lot!! I will use this and tell you about the result!!

---

<div class="post-metadata">

**Author:** ![JvonRudno](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Post date:** [April 25, 2016, 8:07am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/8 "2016-04-25T08:07:43Z")

</div>

Hi Christian, Today I have tested your suggestion and all work perfectly. Thanks a lot!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/delete-a-field-in-filter-but-use-it-in-output/48008/9 "2017-07-06T05:00:48Z")

</div>


