# Disable \_source field from indexing

**URL:** <https://discuss.elastic.co/t/disable-source-field-from-indexing/334486>\
**Category:** Elasticsearch\
**Created:** [May 27, 2023, 5:01am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486 "2023-05-27T05:01:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mhag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhag/32/118090_2.png) [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Post date:** [May 27, 2023, 5:01am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/1 "2023-05-27T05:01:26Z")

</div>

Hi,

To reduce the size of an indice I decide not to store \_source field in elasticsearch, but I got this error when I try to diable it.

```auto
PUT /myindice/_mapping
{
  "properties": {
    "_source": {
      "enabled": false
    }
  }
}

```

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "Field [_source] is defined both as an object and a field"
      }
    ],
    "type": "mapper_parsing_exception",
    "reason": "Field [_source] is defined both as an object and a field"
  },
  "status": 400
}

```

Have anyone an idea what this error does mean ?

I can't get the \_source field in the mapping with

```auto
GET /myindice/_mapping/_source

```

but if I get the details of size of fields it's there

POST myindice/\_disk\_usage?run\_expensive\_tasks=true

```auto
{"field":"_source","total":"10.6mb","tot":"bla",.....}
....

```

Regards.

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [May 27, 2023, 11:17am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/2 "2023-05-27T11:17:30Z")

</div>

Hi @Mhag

You cannot disable an existing index. Create a new index and reindex the data.  
There are such effects when [disabling \_source](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-source-field.html#disable-source-field).

---

<div class="post-metadata">

**Author:** ![Mhag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhag/32/118090_2.png) [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Post date:** [May 27, 2023, 12:15pm UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/3 "2023-05-27T12:15:56Z")

</div>

Hi @RabBit_BR ,

Thanks for the link it's very helpful.

In my situation, Logstash creates the index at the output section. Is there a method to exclude this field when Logstash puts it into Elasticsearch?

```auto
output {
        elasticsearch {
                hosts => ["https://xxxxx:9200"]
                ssl => true
                ssl_certificate_verification => false
                index => "myindice-%{+YYYY.MM.dd}"
                user => "xxxxxx"
                password => "xxxxxxx"
        }
  }

```

Alternatively, should I create a template for the index with a specific mapping?

Best regards.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 27, 2023, 2:51pm UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/4 "2023-05-27T14:51:55Z")

</div>

> [@Mhag](#):
>
> Alternatively, should I create a template for the index with a specific mapping?

Since you are using daily indices you will need to have a template that will be applied when the index is created.

---

<div class="post-metadata">

**Author:** ![Mhag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhag/32/118090_2.png) [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Post date:** [May 28, 2023, 5:16pm UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/5 "2023-05-28T17:16:07Z")

</div>

Thanks,

Is it possible to disable \_source field without using mapping in logstash side ? something like :

```auto
  mutate {
    remove_field => ["_source"]
  }

```

This suppose we can ignore existing indexes with this field.

Regards.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 28, 2023, 11:16pm UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/6 "2023-05-28T23:16:19Z")

</div>

You need to use a template, Logstash cannot do this for you.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 29, 2023, 2:47am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/7 "2023-05-29T02:47:27Z")

</div>

> [@Mhag](#):
>
> Is it possible to disable \_source field without using mapping in logstash side ?

No, this field does not exists in Logstash, it will be created by elasticsearch when it receives an indexing request.

The only way to disable the `_source` field is using a template that will set it to false.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2023, 2:47am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486/8 "2023-06-26T02:47:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
