# Exclude part of kubernetes log

**URL:** <https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 30, 2019, 12:18pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348 "2019-12-30T12:18:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![markrity](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markrity/32/100712_2.png) [@markrity](https://discuss.elastic.co/u/markrity)\
**Post date:** [December 30, 2019, 12:18pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348/1 "2019-12-30T12:18:31Z")

</div>

I'm trying to make Filebeat to exclude part of the whole log that being sent to Logstash through filebeat config xml file.

I have log like this:  
`{ "@timestamp" : "timestamp" , "name" : "general" , "kubernetes" : { "namespace" : "namespace" , "pod" : { "name" : "name" , "uid" : "uid" }, "container" : { "name" : "name" , "image" : "image" }, "node" : { "name" : "name" }, "labels" : { "env" : "env" , "app" : "app" , "pod-template-hash" : "pod-template-hash" , "labels" : "" }, "replicaset" : { "name" : "name" } }, "hostname" : "hostname" , "system" : "system" , "tag" : "tag" , "host" : { "name" : "name" }, "ecs" : { "version" : "version" }, "agent" : { "ephemeral_id" : "ephemeral_id" , "version" : "version" , "hostname" : "hostname" , "id" : "id" , "type" : "filebeat" }, "v" : 0 , "version" : "version" , "pid" : 8 , "stream" : "stdout" , "app" : "app" , "message" : "message" , "time" : "time" , "@version" : "1" , "input" : { "type" : "container" }, "env" : "staging" , "level" : "DEBUG" }`  
I want to remove from this log just the "kubernetes" map part. Is there is a way to do that?  
Since exclude\_line excludes the whole log.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [December 30, 2019, 2:22pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348/2 "2019-12-30T14:22:37Z")

</div>

Have you tried using the `drop_fields` processor? [https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html)

---

<div class="post-metadata">

**Author:** ![markrity](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markrity/32/100712_2.png) [@markrity](https://discuss.elastic.co/u/markrity)\
**Post date:** [December 30, 2019, 4:33pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348/3 "2019-12-30T16:33:32Z")

</div>

@kvch , Thanks for the reply .  
Yes I have tried , adding  
`processors: - drop_fields: fields: ["kubernetes.namespace"]` and also just `kubernetes`  
It drops the whole log instead just this part, got any other ideas ?

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [January 6, 2020, 7:29pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348/4 "2020-01-06T19:29:36Z")

</div>

You have to do it in 2 processors.  
decode\_json and then drop\_fields

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2020, 7:43pm UTC](https://discuss.elastic.co/t/exclude-part-of-kubernetes-log/213348/5 "2020-02-03T19:43:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
