# Hide empty fields imported from Filebeat & winlogbeat template

**URL:** <https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631>\
**Category:** Kibana\
**Created:** [May 16, 2024, 1:28pm UTC](https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631 "2024-05-16T13:28:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 16, 2024, 1:28pm UTC](https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631/1 "2024-05-16T13:28:38Z")

</div>

Hello,

I'm using filebeat and winlogbeat **8.13.2** and have run the setup command for both to import the templates, but it seems to have imported the empty fields and thus kibana is showing them.

It was discussed years ago that [it was a bug](https://discuss.elastic.co/t/hide-unused-fields-in-kibana-discover/239058/3) but years later still the same ?

How to fix this ?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ecbde599be7cdfe6dceafb3bc957d375ec84306d.png)

Thank you for your help !

---

<div class="post-metadata">

**Author:** ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)\
**Post date:** [May 17, 2024, 9:27am UTC](https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631/2 "2024-05-17T09:27:34Z")

</div>

This is unfortunately an issue with how Beats templates work and how Kibana Discover works.

Kibana Discover asks the Beat indices (`filebeat-*` and `winlogbeat-*`) for all the fields in their templates and lists those, splitting it into fields that have data and fields that are empty.

The issue is that Beats use large combined templates, even for fields from modules that aren't enabled so the field list is very big and many are always empty since you're not using those modules.

Luckily you can simply collapse the list of empty fields or use the search bar to find the set of fields you're looking to understand.

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 17, 2024, 9:34am UTC](https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631/3 "2024-05-17T09:34:46Z")

</div>

Thank you !

To solve this definitely, I will look to create a logstash filter that removes empty fields.

---

<div class="post-metadata">

**Author:** ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)\
**Post date:** [May 17, 2024, 11:22am UTC](https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631/4 "2024-05-17T11:22:08Z")

</div>

I'm not sure if that will help, because it's not based on if the fields are empty in the documents, it's that they are defined in the mapping but no documents populate those fields.  
So rather you'd need to edit the mappings I think but that might not work well across upgrades.

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 17, 2024, 11:32am UTC](https://discuss.elastic.co/t/hide-empty-fields-imported-from-filebeat-winlogbeat-template/359631/5 "2024-05-17T11:32:07Z")

</div>

Thanks for the update, so the only solution is to collapse the list from Kibana.
