# Filebeat processors drop\_fields has no effect

**URL:** <https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2023, 1:57am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213 "2023-08-07T01:57:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Drewolf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drewolf/32/124371_2.png) [@Drewolf](https://discuss.elastic.co/u/Drewolf)\
**Post date:** [August 7, 2023, 1:57am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213/1 "2023-08-07T01:57:55Z")

</div>

**background**  
this processors can not drop field "agent\_name"  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15cdb94f83d51a84d04d793e8017576cffc6cd45.png)

**my filebeat config**

```auto
filebeat.inputs:
- type: container
  paths:
    # - /var/log/containers/xgimi-launcher*.log
    - /var/log/containers/*.log
  processors:
    - add_kubernetes_metadata:
        host: ${NODE_NAME}
        matchers:
        - logs_path:
            logs_path: "/var/log/containers/"
    - drop_fields:
        fields: ["kubernetes_labels_app"]

  multiline.type: pattern
  multiline.pattern: '.*exception.*:.*|^[[:space:]]+(at|\.{3})[[:space:]]+\b|^Caused by:'
  multiline.negate: false
  multiline.match: after

# To enable hints based autodiscover, remove `filebeat.inputs` configuration and uncomment this:
#filebeat.autodiscover:
# providers:
# - type: kubernetes
# node: ${NODE_NAME}
# hints.enabled: true
# hints.default_config:
# type: container
# paths:
# - /var/log/containers/*${data.kubernetes.container.id}.log

processors:
  - timestamp:
      field: "@timestamp"
      layouts:
        - '2006-01-02T15:04:05Z'
        - '2006-01-02T15:04:05.999Z'
        - '2006-01-02T15:04:05.999-07:00'
  - drop_fields:
      fields: ["agent_name"]

cloud.id: ${ELASTIC_CLOUD_ID}
cloud.auth: ${ELASTIC_CLOUD_AUTH}

output.kafka:
  # initial brokers for reading cluster metadata
  hosts: ["10.64.99.29:9092", "10.64.99.2:9092", "10.64.99.238:9092"]

  # message topic selection + partitioning
  topic: 'filebeat-chen'
  partition.round_robin:
    reachable_only: false

  required_acks: 1
  compression: gzip
  max_message_bytes: 1000000

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 7, 2023, 2:20am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213/2 "2023-08-07T02:20:27Z")

</div>

Hello and welcome,

What is your final output, after kafka, the source of your screenshot?

Filebeat does not produce fields with underscore, it will produce a json object named `agent` with multiple nested fields, like `name`, `version`, `id` etc.

So you will have `agent.name`, `agent.version`, `agent.id` etc.

Change `agent_name` in your `drop_fields` processor to `agent.name`.

---

<div class="post-metadata">

**Author:** ![Drewolf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drewolf/32/124371_2.png) [@Drewolf](https://discuss.elastic.co/u/Drewolf)\
**Post date:** [August 7, 2023, 3:14am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213/3 "2023-08-07T03:14:00Z")

</div>

thks, this message was reprocessed by graylog extractors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2023, 5:14am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213/4 "2023-09-04T05:14:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
