# How to disable capturing of specific headers only

**URL:** <https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282>\
**Category:** APM\
**Tags:** dotnet\
**Created:** [March 15, 2021, 3:12pm UTC](https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282 "2021-03-15T15:12:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kbalys](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@kbalys](https://discuss.elastic.co/u/kbalys)\
**Post date:** [March 15, 2021, 3:12pm UTC](https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282/1 "2021-03-15T15:12:32Z")

</div>

I would like to skip capturing of some of the request headers. I am aware of of the settings:

`<add key="ElasticApm:CaptureHeaders" value="false"/>`

But this disables capturing of all headers, after that I don't have for example user\_agent.

I would like to skip capturing of only the subset of headers - I would like to remove the Cookie header.

Is it possible to achieve this?

**APM agent dotnet 1.7.1** :

---

<div class="post-metadata">

**Author:** ![GregKalapos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregkalapos/32/37205_2.png) [@GregKalapos](https://discuss.elastic.co/u/GregKalapos)\
**Post date:** [March 15, 2021, 4:49pm UTC](https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282/2 "2021-03-15T16:49:00Z")

</div>

Hi @kbalys,

yes, you can do this. Use the the [`SanitizeFieldNames` setting](https://www.elastic.co/guide/en/apm/agent/dotnet/current/config-core.html#config-sanitize-field-names) for this.

---

<div class="post-metadata">

**Author:** ![kbalys](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@kbalys](https://discuss.elastic.co/u/kbalys)\
**Post date:** [March 15, 2021, 10:24pm UTC](https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282/3 "2021-03-15T22:24:15Z")

</div>

Hi @GregKalapos,

thank you for the answer. As far as I know SanitizeFieldNames setting replaces a value with a placeholder for example I have:  
`"http.request.headers.Accesstoken [REDACTED]"`  
and this value is sent to the index by the agent.

My assumption is that sanitizing fields does not improve performance as much as removing most of the headers?

---

<div class="post-metadata">

**Author:** ![GregKalapos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregkalapos/32/37205_2.png) [@GregKalapos](https://discuss.elastic.co/u/GregKalapos)\
**Post date:** [March 16, 2021, 4:49pm UTC](https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282/4 "2021-03-16T16:49:33Z")

</div>

> As far as I know SanitizeFieldNames setting replaces a value with a placeholder for example I have:  
> "http.request.headers.Accesstoken [REDACTED]"  
> and this value is sent to the index by the agent.  
> My assumption is that sanitizing fields does not improve performance as much as removing most of the headers?

That's right, with this you just mask the values, but it won't help you with performance. If the goal is to minimize runtime overhead then only setting `CaptureHeaders` to `false` will help, there is not setting to only read specific headers or skip reading specific ones. On the other hand if you want to minimize storage and network traffic you could use the [Filter API](https://www.elastic.co/guide/en/apm/agent/dotnet/current/public-api.html#filter-api) - with a little bit of a C# code you can manually remove specific headers and those won't be sent to APM server. But those will still be captured by the agent, so in terms of runtime overhead this won't help.

I hope this helps a bit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2021, 12:49pm UTC](https://discuss.elastic.co/t/how-to-disable-capturing-of-specific-headers-only/267282/5 "2021-04-06T12:49:51Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
