# How to drop the fields that Filebeat normally adds (type, source, offset, etc.)

**URL:** <https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 7, 2018, 4:06am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235 "2018-08-07T04:06:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Junble](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/junble/32/49158_2.png) [@Junble](https://discuss.elastic.co/u/Junble)\
**Post date:** [August 7, 2018, 4:06am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/1 "2018-08-07T04:06:52Z")

</div>

Hi all  
As the title says,but i didn't find the setting about it!

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 3:59pm UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/2 "2018-08-07T15:59:48Z")

</div>

Hi @Junble,

I think the setting you are looking for is the [`drop_fields` processor](https://www.elastic.co/guide/en/beats/filebeat/6.3/drop-fields.html) 🙂

---

<div class="post-metadata">

**Author:** ![chandra0651](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra0651/32/30484_2.png) [@chandra0651](https://discuss.elastic.co/u/chandra0651)\
**Post date:** [August 7, 2018, 4:05pm UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/3 "2018-08-07T16:05:36Z")

</div>

Prune filter and mutate filter will also work with remove\_fields.

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [August 8, 2018, 6:05am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/4 "2018-08-08T06:05:23Z")

</div>

Hi @Junble ,

You can drop other fields except "type" and "@timestamp", Because these are the mandatory and default field of filebeat. drop\_fields processor also can't drop these two fields

---

<div class="post-metadata">

**Author:** ![Junble](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/junble/32/49158_2.png) [@Junble](https://discuss.elastic.co/u/Junble)\
**Post date:** [August 8, 2018, 11:12am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/5 "2018-08-08T11:12:07Z")

</div>

Hi @jsoriano  
Thank you, that's what I was looking for!

---

<div class="post-metadata">

**Author:** ![Junble](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/junble/32/49158_2.png) [@Junble](https://discuss.elastic.co/u/Junble)\
**Post date:** [August 8, 2018, 11:18am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/6 "2018-08-08T11:18:19Z")

</div>

Thank you! I'll try it!

---

<div class="post-metadata">

**Author:** ![Junble](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/junble/32/49158_2.png) [@Junble](https://discuss.elastic.co/u/Junble)\
**Post date:** [August 8, 2018, 11:19am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/7 "2018-08-08T11:19:02Z")

</div>

OK,I see, thank you very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2018, 11:19am UTC](https://discuss.elastic.co/t/how-to-drop-the-fields-that-filebeat-normally-adds-type-source-offset-etc/143235/8 "2018-09-05T11:19:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
