# Filebeat - drop fields processor doesn't remove agent.\* and ecs fields. (Without Logstash)

**URL:** <https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985>\
**Category:** Beats\
**Created:** [September 25, 2019, 7:51am UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985 "2019-09-25T07:51:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![turgayozgur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/turgayozgur/32/54841_2.png) [@turgayozgur](https://discuss.elastic.co/u/turgayozgur)\
**Post date:** [September 25, 2019, 7:51am UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985/1 "2019-09-25T07:51:07Z")

</div>

The drop fields section is working for the other fields like kubernetes.pod.id but it is not working for agent.\* and ecs fields.

Any workaround here?

- Version: 7.3.2
- Operating System: Linux
- Steps to Reproduce: Apply the config below.

```auto
filebeatConfig:
  filebeat.yml: |
    filebeat.config:
      modules:
        path: ${path.config}/modules.d/*.yml
        # Reload module configs as they change:
        reload.enabled: false
    
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          templates:
            - condition.and:
                - equals.kubernetes.labels.log-group: xxx
              config:
                - type: container
                  paths:
                    - '/var/lib/docker/containers/${data.kubernetes.container.id}/*.log'
                  processors:
                  - drop_fields:
                       fields: ["agent.ephemeral_id", "agent.hostname", "agent.id", "agent.type", "agent.version", "ecs.version", "input.type", "log.offset"]

    output.elasticsearch:
      hosts: '${ELASTICSEARCH_HOSTS:elasticsearch-master:9200}'

```

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [October 2, 2019, 11:22am UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985/2 "2019-10-02T11:22:15Z")

</div>

hi @turgayozgur, can you first check if identation is an issue here (I see it is missing before

`- drop_fields`)

Ex

```
processors:
 - drop_fields:
     when:
        condition
     fields: ["field1", "field2", ...]
     ignore_missing: false
```

---

<div class="post-metadata">

**Author:** ![turgayozgur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/turgayozgur/32/54841_2.png) [@turgayozgur](https://discuss.elastic.co/u/turgayozgur)\
**Post date:** [October 2, 2019, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985/3 "2019-10-02T16:42:28Z")

</div>

Hi, no difference 😕

---

<div class="post-metadata">

**Author:** ![alexclifford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexclifford/32/54957_2.png) [@alexclifford](https://discuss.elastic.co/u/alexclifford)\
**Post date:** [October 13, 2019, 11:44am UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985/4 "2019-10-13T11:44:49Z")

</div>

Same for me, these fields can't be dropped by Filebeat or Functionbeat when I try with `drop_fields`. Also version 7.4.0.

```auto
agent.ephemeral_id
agent.hostname
agent.id
agent.type
agent.version
ecs.version
host.name

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2019, 1:44pm UTC](https://discuss.elastic.co/t/filebeat-drop-fields-processor-doesnt-remove-agent-and-ecs-fields-without-logstash/200985/5 "2019-11-10T13:44:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
