# Drop\_fields and the beats.name/.hostname/.version fields

**URL:** <https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 12, 2017, 10:21pm UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450 "2017-12-12T22:21:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![geckofish](https://avatars.discourse-cdn.com/v4/letter/g/898d66/32.png) [@geckofish](https://discuss.elastic.co/u/geckofish)\
**Post date:** [December 12, 2017, 10:21pm UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/1 "2017-12-12T22:21:45Z")

</div>

Hi There,

I'm using Metricbeat, Elastic Search and Kibana to create system overview dashboards of about 45 Linux boxes.

I'm trying to keep the data to the necessities, so I'm stripping out as much data as possible using drop\_fields.

I'm using these filters on the systems module in :

```
- drop_fields:
       fields: [ "beat.version", "metricset.module", "metricset.rtt", "host", "system.load.norm.5", "system.load.5", "system.load.norm.15", "system.load.15", "system.load.norm.1"

```

However I can't find a way to get rid of the 'beat' fields, I've tried various things like this:

```auto
*beat* 
beat.* 
beat.hostname 
*.hostname

```

Equally, has anyone any idea if I can do anything with the \_ fields? I suspect these are required, I'm just trying to shave anything I can to keep costs down and performance on the elasticsearch box up 🙂

```
{
  "_index": "metricbeat-2017.12.12",
  "_type": "logs",
  "_id": "AWBMlbcud7P8UCMuIZjH",
  "_version": 1,
  "_score": null,
  "_source": {
    "@timestamp": "2017-12-12T21:16:07.321Z",
    "system": {
      "load": {
        "1": 0,
        "cores": 2,
        "norm": {
          "1": 0
        }
      }
    },
    "beat": {
      "name": "supportserver",
      "hostname": "supportserver",
      "version": "6.0.1"
    },
    "@version": "1",
    "host": "supportserver",
    "metricset": {
      "name": "load"
    },
    "tags": [
      "beats_input_raw_event"
    ]
  },
  "fields": {
    "@timestamp": [
      1513113367321
    ]
  },
  "highlight": {
    "metricset.name": [
      "@kibana-highlighted-field@load@/kibana-highlighted-field@"
    ]
  },
  "sort": [
    1513113367321
  ]
}

```

Thanks in advance for any help 🙂  
Mike

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 13, 2017, 3:49pm UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/2 "2017-12-13T15:49:18Z")

</div>

> [@geckofish](#):
>
> However I can't find a way to get rid of the 'beat' fields

Does it work if you use this?

```auto
- drop_fields:
    fields: [beat]

```

> [@geckofish](#):
>
> any idea if I can do anything with the \_ fields?

Those are not sent by Beats. They are part of Elasticsearch. [Index API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-index_.html)

---

<div class="post-metadata">

**Author:** ![geckofish](https://avatars.discourse-cdn.com/v4/letter/g/898d66/32.png) [@geckofish](https://discuss.elastic.co/u/geckofish)\
**Post date:** [December 13, 2017, 4:52pm UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/3 "2017-12-13T16:52:29Z")

</div>

Trying just 'beat' doesn't work I'm afraid. Tried with and without quotes, currently looks like this in my config:

```
  - drop_fields:
      fields: [beat, "system.beat.name", "*name*", "beat.version", "metricset.module", "metricset.rtt", "host", "system.load.norm.5", "system.load.5", "system.load.norm.15", "system.load.15", "system.load.norm.1"]

```

Thanks for your reply 🙂

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 13, 2017, 7:24pm UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/4 "2017-12-13T19:24:35Z")

</div>

Try putting into `metricbeat.yml`

```auto
processors:
- drop_fields:
    fields: [beat]

```

This works for me when setting it at the global level on Metricbeat 6.0.1.

It didn't work at the module level. I assume this is because the `beat` object isn't added until later in the pipeline.

---

<div class="post-metadata">

**Author:** ![geckofish](https://avatars.discourse-cdn.com/v4/letter/g/898d66/32.png) [@geckofish](https://discuss.elastic.co/u/geckofish)\
**Post date:** [December 14, 2017, 11:00am UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/5 "2017-12-14T11:00:18Z")

</div>

Yup! That did the trick.

Oddley, I've lost 'host' even after having removed it from my module sided filters, but I think I can handle that with one tag per host anyway.

Thanks for your help!

P.s: Is there some way I can contribute to the documentation? I feel like this should be mentioned as a footnote on the drop\_fields section on the individual module pages.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 18, 2017, 6:02am UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/6 "2017-12-18T06:02:28Z")

</div>

> [@geckofish](#):
>
> P.s: Is there some way I can contribute to the documentation?

It's all open source and contained in [GitHub - elastic/beats: 🐠 Beats - Lightweight shippers for Elasticsearch & Logstash](https://github.com/elastic/beats) so you can open a PR with suggested edits. From the docs on the [elastic.co](http://elastic.co) site there are edit links on the right side of every section. Clicking that link takes you directly to github web editor for the page (if you are signed into github).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 6:02am UTC](https://discuss.elastic.co/t/drop-fields-and-the-beats-name-hostname-version-fields/111450/7 "2018-01-15T06:02:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
