# Elasticsearch remove fields

**URL:** <https://discuss.elastic.co/t/elasticsearch-remove-fields/289442>\
**Category:** Kibana\
**Created:** [November 17, 2021, 12:01pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442 "2021-11-17T12:01:45Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 17, 2021, 12:01pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/1 "2021-11-17T12:01:45Z")

</div>

Hello!  
i'm using:  
elasticsearch 7.13.2  
kibana 7.12.1

I am trying to remove index pattern fields in kibana -\> dev tools using the following command

> POST /mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex/\_update\_by\_query?conflicts=proceed  
> {  
> "script" : "ctx.\_source.remove("new\_field3")"  
> }

But it didn't work. Although, if I try to add a field, then I can do it using the following command

> POST /mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex/\_update\_by\_query?conflicts=proceed  
> {  
> "script" : "ctx.\_source.new\_field66 = 'value\_of\_new\_field6'"  
> }

Please tell me what I'm doing wrong

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 17, 2021, 12:33pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/2 "2021-11-17T12:33:35Z")

</div>

What is it doing when you try to run it?

`("new_field3")` needs to be `('new_field3')` since it's wrapped in `"`.

```auto
POST /mdaemon_test_array_2_step-2021.11.16_test_reindex/_update_by_query?conflicts=proceed
{
"script" : "ctx._source.remove('new_field3')"
}

```

---

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 17, 2021, 1:28pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/3 "2021-11-17T13:28:25Z")

</div>

Thanks for the answer. I tried your command, but the field remains

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/293671006673f7f3d92c8acf233b087b0a6e877f.png)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 17, 2021, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/4 "2021-11-17T13:37:15Z")

</div>

What do you see when you run this?

```auto
GET mdaemon_test_array_2_step-2021.11.16_test_reindex/_search
{
  "_source": [
    "new_field3"
  ]
}

```

---

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 17, 2021, 1:39pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/5 "2021-11-17T13:39:16Z")

</div>

> [@aaron-nimocks](#):
>
> ```auto
> GET mdaemon_test_array_2_step-2021.11.16_test_reindex/_search
> {
> "_source": [
> "new_field3"
> ]
> }
> 
> ```

> #! Elasticsearch built-in security features are not enabled. Without authentication, your cluster could be accessible to anyone. See [Set up minimal security for Elasticsearch | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/security-minimal-setup.html) to enable security.  
> {  
> "took" : 10,  
> "timed\_out" : false,  
> "\_shards" : {  
> "total" : 1,  
> "successful" : 1,  
> "skipped" : 0,  
> "failed" : 0  
> },  
> "hits" : {  
> "total" : {  
> "value" : 10000,  
> "relation" : "gte"  
> },  
> "max\_score" : 1.0,  
> "hits" : [  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "YUwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "YkwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "Y0wrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "ZEwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "ZUwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "ZkwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "Z0wrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "aEwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "aUwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> },  
> {  
> "\_index" : "mdaemon\_test\_array\_2\_step-2021.11.16\_test\_reindex",  
> "\_type" : "\_doc",  
> "\_id" : "akwrKX0B6KcywX5P2CJp",  
> "\_score" : 1.0,  
> "\_source" : { }  
> }  
> ]  
> }  
> }

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 17, 2021, 1:40pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/6 "2021-11-17T13:40:38Z")

</div>

So it worked.

If you are looking at `deleted: 0` of an indication it didn't work that's not what that means. That's the count of entire records deleted which should be 0. You were just deleting 1 field in the record which would be an update. All of your records were updated so it's a good indication it worked.

---

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 17, 2021, 1:46pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/7 "2021-11-17T13:46:48Z")

</div>

If I remove them, then why then do I see these fields in discover and index patterns?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9d31e3498c30071a454fa7fcd467125ac8ea646c.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/53f510d340239616cd1e695106758b52ede1c982.png)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 17, 2021, 1:48pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/8 "2021-11-17T13:48:56Z")

</div>

Refresh or delete/create your index pattern to see if it's still there. Not sure if your version requires that, newest ones auto updates.

---

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 18, 2021, 6:27am UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/9 "2021-11-18T06:27:15Z")

</div>

I tried "delete/create" in "index patterns" but it gave no results.  
I tried the "refresh index" in the "index managment" but it gave no results.  
If I delete index and create it (in the index managment), then it deletes all the fields that I manually created, and I only need to delete a specific field. Also it will delete all the data that was in it, but it doesn't suit me

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 18, 2021, 12:35pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/10 "2021-11-18T12:35:04Z")

</div>

I think you might have something else going on then.

If you run this query in dev tools and you don't find any field with that name then that field does not exist in the data.

```auto
GET mdaemon_test_array_2_step-2021.11.16_test_reindex/_search
{
  "_source": [
    "new_field3"
  ]
}

```

Can you post what your index pattern is named and how you deleted and recreated?

---

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 22, 2021, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/11 "2021-11-22T10:57:47Z")

</div>

I delete it in kibana (as in the screenshot), create it in "Index Patterns" -\> "Create index patters"  
p.s.  
There is no data in the "new\_field3" field, if it matters

 ![delete](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1cd604146d71d613d43c2dce537a68b201fdd5af.png)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 22, 2021, 1:08pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/12 "2021-11-22T13:08:54Z")

</div>

Is there a data pipeline that is constantly feeding data to this index?

---

<div class="post-metadata">

**Author:** ![hellotty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hellotty/32/93445_2.png) [@hellotty](https://discuss.elastic.co/u/hellotty)\
**Post date:** [November 22, 2021, 2:27pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/13 "2021-11-22T14:27:22Z")

</div>

No, this is a copied inidex. No information goes there

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2021, 2:27pm UTC](https://discuss.elastic.co/t/elasticsearch-remove-fields/289442/14 "2021-12-20T14:27:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
