# How to overwrite/rewrite message field after kv and remove field filters?

**URL:** <https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647>\
**Category:** Logstash\
**Created:** [April 18, 2016, 12:15pm UTC](https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647 "2016-04-18T12:15:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [April 18, 2016, 12:15pm UTC](https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647/1 "2016-04-18T12:15:24Z")

</div>

Hi Experts,

I need to overwrite my message field once I am done with kv filter . My flow would be like

```
input{}
filter {
grok { match=>["message",'CEF:%{CEFNUM:cef}[^\|\n]*\|%{CEFBAR:dvcvendor}\|%{CEFBAR:dvcproduct}\|%{CEFBAR:dvcversion}\|%{CEFBAR:alert}\|%{CEFDEV:alertmsg}[^\|\n]*\|%{CEFDEV:sev}[^\|\n]*\|'] }    
kv { 
   source => "message"
   field_split => "\s"
}
mutate {remove_field => ["customerID","customerURI","modelConfidence","relevance"]}
grok {overwrite => ["message"]}
}

```

Here last grok filter is not working the way I want I still can see 4 fields in the message field .So idea is to overwrite final message field which does not have 4 fields in it .Please suggest how i can achieve this .

Thanks  
VG

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 5:51am UTC](https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647/2 "2016-04-19T05:51:04Z")

</div>

What do you want to overwrite the `message` field with? Using both grok and kv on the same field is a bit weird. If you can give an example log message it'll be easier to help.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [April 19, 2016, 6:17am UTC](https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647/3 "2016-04-19T06:17:52Z")

</div>

So my original Message holds following, I have highlighted 4 fields which I want to remove.

> Message: Mar 31 01:03:40 172.24.11.72 CEF:0|Check Point|VPN-1 & FireWall-1||drop|drop|High| eventId=23985829711 mrt=1459367155677 proto=TCP **customerID=SO1jaHkUBABCK9DnjD5Ep6A customerURI=/XXX modelConfidence=asdkjdkjsdj relevance=blabla** categorySignificance=/Informational/Warning categoryBehavior=/Access categoryDeviceGroup=/Firewall catdt=Firewall categoryOutcome=/Failure categoryObject=/Host/Application/Service modelConfidence=0 severity=5 relevance=10 assetCriticality=0 priority=High

What I want to see is a modified message field which should not have 4 fields(customerID,customerURI,modelConfidence and relevance) in it.

> Message:Mar 31 01:03:40 172.24.11.72 CEF:0|Check Point|VPN-1 & FireWall-1||drop|drop|High| eventId=23985829711 mrt=1459367155677 proto=TCP categorySignificance=/Informational/Warning categoryBehavior=/Access categoryDeviceGroup=/Firewall catdt=Firewall categoryOutcome=/Failure categoryObject=/Host/Application/Service modelConfidence=0 severity=5 relevance=10 assetCriticality=0 priority=High

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 8:31am UTC](https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647/4 "2016-04-19T08:31:27Z")

</div>

Perhaps you can just use the mutate filter's gsub option?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/how-to-overwrite-rewrite-message-field-after-kv-and-remove-field-filters/47647/5 "2017-07-06T05:01:39Z")

</div>


