# Drop multiple fields with regex on field names using filebeat

**URL:** <https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 6, 2017, 10:28am UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496 "2017-12-06T10:28:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Haughtton](https://avatars.discourse-cdn.com/v4/letter/h/e9bcb4/32.png) [@Haughtton](https://discuss.elastic.co/u/Haughtton)\
**Post date:** [December 6, 2017, 10:28am UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496/1 "2017-12-06T10:28:57Z")

</div>

Hello,

I'm trying to send a big json file through filebeat to elasticsearch but I have too many fields so I want to drop a lot a them.

I saw on the doc that I can do this using the filebeat processor and I did smthing like this :

processors:

- drop\_fields:  
when:  
or:  
- regexp:  
thefield\_name\_randomstring: "test._"  
- regexp:  
thefield\_name\_itsthebest: "test._"  
fields: ["thefield\_name\_itsthebest", "thefield\_name\_randomstring"]

It works fine but since I want to drop a lot of fields , I wanted to use a regex to drop them so do smthing like this :

processors:

- drop\_fields:  
when:  
- regexp:  
thefield\_name\__: "_"  
fields: ["thefield\_name\_\*"]

So I can drop all fields names starting with the name "thefield\_name\_" and I dont care about the value of the fields. But it does not work ☹

**Is there a way to do this ? Or am I doing this the wrong way and shouldn't use filebeats processors to do that ?**

Note that I can't use logstash ☹

Thank you !

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 6, 2017, 2:47pm UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496/2 "2017-12-06T14:47:10Z")

</div>

I don't think you can select the fields to drop via regex. There is also an include\_fields processor, which drops all fields but the configured ones.

---

<div class="post-metadata">

**Author:** ![Haughtton](https://avatars.discourse-cdn.com/v4/letter/h/e9bcb4/32.png) [@Haughtton](https://discuss.elastic.co/u/Haughtton)\
**Post date:** [December 6, 2017, 3:02pm UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496/3 "2017-12-06T15:02:06Z")

</div>

Hm ok thank you..

The thing is that I want to keep smthing like 250 fields and drop 300 so this is not cool haha I'm guessing this is a common problem so how is it fixed normally ? better mapping ? Not using filebeat but logstash ?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 7, 2017, 12:30pm UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496/4 "2017-12-07T12:30:41Z")

</div>

Wow, that's quite a number of fields. The [prune](https://www.elastic.co/guide/en/logstash/current/plugins-filters-prune.html) filter in logstash seems to support regular expressions. Feel free to [open an enhancement request](https://github.com/elastic/beats/issues) for beats to provide the same functionality.

---

<div class="post-metadata">

**Author:** ![Haughtton](https://avatars.discourse-cdn.com/v4/letter/h/e9bcb4/32.png) [@Haughtton](https://discuss.elastic.co/u/Haughtton)\
**Post date:** [December 7, 2017, 2:14pm UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496/5 "2017-12-07T14:14:13Z")

</div>

Yeah i know ☹

Ok ! Thx very much for the answers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2017, 10:29am UTC](https://discuss.elastic.co/t/drop-multiple-fields-with-regex-on-field-names-using-filebeat/110496/6 "2017-12-27T10:29:19Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
