# How to add/remove fields in index pattern

**URL:** <https://discuss.elastic.co/t/how-to-add-remove-fields-in-index-pattern/152691>\
**Category:** Kibana\
**Created:** [October 16, 2018, 3:13pm UTC](https://discuss.elastic.co/t/how-to-add-remove-fields-in-index-pattern/152691 "2018-10-16T15:13:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kritikajj](https://avatars.discourse-cdn.com/v4/letter/k/41988e/32.png) [@kritikajj](https://discuss.elastic.co/u/kritikajj)\
**Post date:** [October 16, 2018, 3:13pm UTC](https://discuss.elastic.co/t/how-to-add-remove-fields-in-index-pattern/152691/1 "2018-10-16T15:13:10Z")

</div>

Hi,

I have ELK stack 6.2.2 installed and filebeat 6.4.1. I am using filebeat to send logs from "Loader" application installed on windows to ELK. The index fields I see in my Kibana Index Pattern, have fields like kubernetes, IIS, apache/traefik (snapshot of few attached) which I don't want. How can I remove these fields and add new fields which I need.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6cc3675a167c8abc3ae0ad8a4ba8df50d89c98c3.png)

Can someone pls help here!

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [October 16, 2018, 10:02pm UTC](https://discuss.elastic.co/t/how-to-add-remove-fields-in-index-pattern/152691/2 "2018-10-16T22:02:03Z")

</div>

I believe that [index mappings](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/mapping.html) are used to created kibana's index patterns. (May want to ask over in [kibana](https://discuss.elastic.co/c/kibana) to be sure).

Assuming that ^^ is correct updating the mappings will influence the index patterns. Unless those fields in question are dynamic mappings, created because there is actual data in the index for those fields.

If that is the case, you can use [Logstash's remove field](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-remove_field) to prevent that data from getting to the index, or you can use the [Ingest node's remove processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/remove-processor.html).

---

<div class="post-metadata">

**Author:** ![kritikajj](https://avatars.discourse-cdn.com/v4/letter/k/41988e/32.png) [@kritikajj](https://discuss.elastic.co/u/kritikajj)\
**Post date:** [October 17, 2018, 11:24am UTC](https://discuss.elastic.co/t/how-to-add-remove-fields-in-index-pattern/152691/3 "2018-10-17T11:24:16Z")

</div>

There is nothing in log file related to IIS or apache. and Neither Dynamic mapping has been configured.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2018, 11:30am UTC](https://discuss.elastic.co/t/how-to-add-remove-fields-in-index-pattern/152691/4 "2018-11-14T11:30:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
