# How do you remove (or not send) metadata from filebeat to logstash?

**URL:** <https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 25, 2019, 6:38pm UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090 "2019-09-25T18:38:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![meatwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/meatwad/32/36031_2.png) [@meatwad](https://discuss.elastic.co/u/meatwad)\
**Post date:** [September 25, 2019, 6:38pm UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090/1 "2019-09-25T18:38:23Z")

</div>

Hi there. I am testing out filebeat on my Mac and it's successfully sending logs to logstash. Is there a way to only send the raw log message and not include any of the metadata?

For example, here's what I get once it's processed by logstash and written to an output file:

2019-09-25T18:21:31.177Z {name=myhostname.local, hostname=myhostname.local, id=x-x-x-x-x, os={name=Mac OS X, family=darwin, build=18G95, version=10.14.6, kernel=18.7.0, platform=darwin}, architecture=x86\_64} 2019-09-25 12:21:29-06 myhostname softwareupdated[609]: Removing client SUUpdateServiceClient pid=32672, uid=0, installAuth=NO rights=(), transactions=0 (/usr/sbin/softwareupdate)

I don't need the info about my node -- I just want the log message as it originally existed. I don't know if it can be excluded on the filebeat side or if it needs to be filtered out at the logstash level.

Any suggestions would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [September 26, 2019, 10:32pm UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090/2 "2019-09-26T22:32:43Z")

</div>

You can do it with processors ([https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html)). Also you can comment out the add\_host\_metadata (see below) option.

```
processors:
  - drop_fields:
      fields: ["ecs.version", "agent.version", "agent.type", "agent.id", "agent.hostname", "input.type"]

  # - add_host_metadata: ~
  # - add_cloud_metadata: ~
```

---

<div class="post-metadata">

**Author:** ![meatwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/meatwad/32/36031_2.png) [@meatwad](https://discuss.elastic.co/u/meatwad)\
**Post date:** [September 29, 2019, 4:10am UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090/3 "2019-09-29T04:10:25Z")

</div>

That did the trick -- thank you very much!

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [September 30, 2019, 8:19pm UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090/4 "2019-09-30T20:19:30Z")

</div>

Happy to help. Please close this topic by accepting the solution.

Thanks  
Abhishek

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2019, 8:19pm UTC](https://discuss.elastic.co/t/how-do-you-remove-or-not-send-metadata-from-filebeat-to-logstash/201090/5 "2019-10-28T20:19:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
