# Filebeat didn't drop some of the fields like agent.\*, ecs.\* etc

**URL:** <https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [August 5, 2020, 6:04pm UTC](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911 "2020-08-05T18:04:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohanr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanr/32/73317_2.png) [@mohanr](https://discuss.elastic.co/u/mohanr)\
**Post date:** [August 5, 2020, 6:04pm UTC](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911/1 "2020-08-05T18:04:20Z")

</div>

Hi,

I am using filebeat with a docker processor. Filebeat generate some fields like agent, ecs etc. I am trying to remove these fields using drop\_fields processor.

```
filebeat.inputs:
- type: docker
  containers.ids: 
    - '*'
  processors:
  - add_docker_metadata: ~
  - drop_fields:
      fields: ["container.image","container.labels", "agent.ephemeral_id", "agent.version", 
      "ecs.version"]
      ignore_missing: true
  setup.dashboards.enabled: true

```

First two fields i.e `container.image, container.labels` are emoved but rest are not.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 10, 2020, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911/2 "2020-08-10T15:46:41Z")

</div>

The fields `agent.ephemeral_id`, `agent.version` and `ecs.version` are added later in the processing pipeline. In order to remove those you need to add a `drop_fields` processor to the global level.

```auto
filebeat.inputs:
- type: docker
  containers.ids: 
    - '*'
  processors:
  - add_docker_metadata: ~
  - drop_fields:
      fields: ["container.image","container.labels"]
      ignore_missing: true

processors:
- drop_fields:
    fields: ["agent.ephemeral_id", "agent.version", "ecs.version"]
    ignore_missing: true

setup.dashboards.enabled: true

```

---

<div class="post-metadata">

**Author:** ![mohanr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanr/32/73317_2.png) [@mohanr](https://discuss.elastic.co/u/mohanr)\
**Post date:** [August 11, 2020, 11:52am UTC](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911/3 "2020-08-11T11:52:53Z")

</div>

Thank you so much. Its working 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2020, 1:52pm UTC](https://discuss.elastic.co/t/filebeat-didnt-drop-some-of-the-fields-like-agent-ecs-etc/243911/4 "2020-09-08T13:52:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
