# How to remove certain fields from filebeat index

**URL:** <https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 17, 2020, 7:47am UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597 "2020-07-17T07:47:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Post date:** [July 17, 2020, 7:47am UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/1 "2020-07-17T07:47:22Z")

</div>

Hi Team,

I am new to Elasticsearch and we are running a POC on Elasticsearch. We would like to remove few fields from the index documents which are not relevant. Please help us to remove this from newly creating index and existing index.

I looked at the kibana-\>management/elasticsearch/index\_management/Templates and could see those fields , can i remove it from there so that its not created for new index.

Thanks,  
Jijo John

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [July 17, 2020, 8:20am UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/2 "2020-07-17T08:20:03Z")

</div>

Hello John,  
You should use the drop\_fields processor.  
[https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html)  
Example:

```auto
processors:
  - drop_fields:
      fields: ["host.name", "ecs.version", "agent.version", "agent.type", "agent.id", "agent.ephemeral_id", "agent.hostname", "input.type"]
# - add_host_metadata: ~
# - add_cloud_metadata: ~

```

---

<div class="post-metadata">

**Author:** ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Post date:** [July 17, 2020, 3:24pm UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/3 "2020-07-17T15:24:20Z")

</div>

> [@kumarabhi](#):
>
> `ecs.version", "agent.vers`

Thank you Very much Abhishek. We will try this and confirm soon.

---

<div class="post-metadata">

**Author:** ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Post date:** [July 18, 2020, 5:29pm UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/4 "2020-07-18T17:29:01Z")

</div>

Its working fine. thank you.

Can we apply similar settings at elasticsearch server instead of editing this at clients (beats)

---

<div class="post-metadata">

**Author:** ![kumarabhi](https://avatars.discourse-cdn.com/v4/letter/k/6a8cbe/32.png) [@kumarabhi](https://discuss.elastic.co/u/kumarabhi)\
**Post date:** [July 28, 2020, 8:16pm UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/5 "2020-07-28T20:16:20Z")

</div>

Hi John,  
Yes it is possible to apply this setting at ElasticSearch server.  
Please refer  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-field-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-field-mapping.html)

FYI, disabling it at client level reduces the data that is transferred to ElasticSearch as well as puts less burden on ElasticSearch server to ignore fields.

Please consider the above point before coming to final decision.

Thanks  
Abhishek

---

<div class="post-metadata">

**Author:** ![jijo.john](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@jijo.john](https://discuss.elastic.co/u/jijo.john)\
**Post date:** [July 30, 2020, 10:16am UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/6 "2020-07-30T10:16:04Z")

</div>

Thank you Abhishek. We are planning to have it disabled at client level only

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2020, 12:16pm UTC](https://discuss.elastic.co/t/how-to-remove-certain-fields-from-filebeat-index/241597/7 "2020-08-27T12:16:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
