# Excluding fields from \_source to avoid storing files

**URL:** <https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241>\
**Category:** Elasticsearch\
**Created:** [November 10, 2017, 9:06pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241 "2017-11-10T21:06:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fnareva](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@fnareva](https://discuss.elastic.co/u/fnareva)\
**Post date:** [November 10, 2017, 9:06pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/1 "2017-11-10T21:06:59Z")

</div>

Is there anything horribly wrong with that?  
I'm trying to get files indexed (via ingest attachment plugin)and searchable, but not stored in ES.  
Likeso:

> ```
> "_source": {
> "excludes":[
> "data","attachment.content"]
> }
> 
> ```

Done a test run, it's behaving as expected, searchable and not in the index.  
Opinions?

Thanks for the time and effort 🙂

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 10, 2017, 11:14pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/2 "2017-11-10T23:14:49Z")

</div>

I’d prefer using a remove processor in the ingest pipeline.

---

<div class="post-metadata">

**Author:** ![Vikas\_Mestry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_mestry/32/42301_2.png) [@Vikas\_Mestry](https://discuss.elastic.co/u/Vikas_Mestry)\
**Post date:** [November 10, 2017, 11:23pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/3 "2017-11-10T23:23:25Z")

</div>

> [@dadoonet](#):
>
> I’d prefer using a remove processor in the ingest pipeline.

Would the remove processor still keep the data of the field indexed & not store, does that mean that remove processor only removes the field from the source whereas the value is persisted in the index ?

Sorry for hijacking this thread but the question came out of curiosity.

Thanks,  
Vikas

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 10, 2017, 11:37pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/4 "2017-11-10T23:37:20Z")

</div>

ah. My answer was may be bad.

I thought the goal was to remove the base64 content only.

One of the thing I dislike with exclusion is that it will give you very bad results if at some point you want to use the reindex api.

---

<div class="post-metadata">

**Author:** ![Vikas\_Mestry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_mestry/32/42301_2.png) [@Vikas\_Mestry](https://discuss.elastic.co/u/Vikas_Mestry)\
**Post date:** [November 10, 2017, 11:56pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/5 "2017-11-10T23:56:33Z")

</div>

Thanks for clarifying,

So in the OP's case, he only has the option to perform an "index" & "updates" to the index will loose the data in the index for the said field.

We can use the reindex api to copy / overwrite the documents from another index to the orignal index then, would that be a good way to do this.

---

<div class="post-metadata">

**Author:** ![fnareva](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@fnareva](https://discuss.elastic.co/u/fnareva)\
**Post date:** [November 13, 2017, 4:07pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/6 "2017-11-13T16:07:42Z")

</div>

Thank you both for your answers.  
Okay - I think I see the issue here.  
Since neither base64 nor the actual file will be stored in the index, if we try to copy the document to another index via reindex api we won't be able to do so reliably for the terms of the file itself, as reindex api works with \_source to do the copy.  
Now if a user wants to upload a different document by 'editing' the existing one we would simply re-index it into segments and re-exclude it again. We are also only excluding the source fields related to that file, so we should also still be able to update the document with new/changed metadata fields (assigned tags and categories, who is it shared with etc).  
That sound right?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2017, 4:07pm UTC](https://discuss.elastic.co/t/excluding-fields-from-source-to-avoid-storing-files/107241/7 "2017-12-11T16:07:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
