# Help with reducing mapping

**URL:** <https://discuss.elastic.co/t/help-with-reducing-mapping/262394>\
**Category:** Kibana\
**Created:** [January 27, 2021, 4:15pm UTC](https://discuss.elastic.co/t/help-with-reducing-mapping/262394 "2021-01-27T16:15:10Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![DavidoffX](https://avatars.discourse-cdn.com/v4/letter/d/eb9ed0/32.png) [@DavidoffX](https://discuss.elastic.co/u/DavidoffX)\
**Post date:** [January 29, 2021, 12:35pm UTC](https://discuss.elastic.co/t/help-with-reducing-mapping/262394/8 "2021-01-29T12:35:17Z")

</div>

@Badger I've done some more testing and I was incorrect about the mapping changing. Having false as the value for dynamic **does** actually prevent the mapping changing, but the data seen in kibana appears to be the full \_source of the data from logstash into elasticsearch. The values are persisted in elastic even though they arent indexed, or changes made to the mapping.

So am back to needing to find a way to reduce the payload from logstash to elasticsearch. I need to remove subkeys from the kubernetes top level field. As discussed previously this isnt possible with the prune filter, but I'm thinking it **should** be possible, maybe using ruby, like you recommended here:

> [@How to dynamically move nested key value to root level](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006):
>
> This is my logstash config file: input { http { id =\> bulkHttpInput port =\> 8088 additional\_codecs =\> {"application/json" =\> "es\_bulk"} codec =\> es\_bulk } } filter { mutate { remove\_field =\> ["headers"] } } output { elasticsearch { id =\> elasticOutputOfHttp index =\> "%{[@metadata][\_index]}" document\_type =\> "%{[@metadata][\_type]}" document\_id =\> "%{[doc][docID]}" doc\_as\_upsert =\> "true" } } and the output is like : { "host" =\> "127.0.0.1", "@…

---

_[View the full topic](https://discuss.elastic.co/t/help-with-reducing-mapping/262394)._
