# How to remove dynamical field?

**URL:** <https://discuss.elastic.co/t/how-to-remove-dynamical-field/46772>\
**Category:** Logstash\
**Created:** [April 8, 2016, 7:33am UTC](https://discuss.elastic.co/t/how-to-remove-dynamical-field/46772 "2016-04-08T07:33:23Z")\
**Posts on this page:** 1\
**Showing post:** 12

<div class="post-metadata">

**Author:** ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)\
**Post date:** [April 11, 2016, 6:32am UTC](https://discuss.elastic.co/t/how-to-remove-dynamical-field/46772/12 "2016-04-11T06:32:34Z")

</div>

Count from the message beginning of the number of sixth .  
but i don't know how to make logstash to do ?

for example,  
{ "message" =\> "..",  
"host" =\> "10.10.10.13",  
"@version" =\> "1",  
"@timestamp" =\> "2016-04-08T06:22:17.711Z",  
"type" =\> "snmptrap",  
"MSDP-MIB::msdpPeerState\_10\_10\_11\_90" =\> "1",  
"field\_7"=\>"field\_7 content",  
"source\_ip" =\> "10.10.10.13"  
}

i want to pick the sixth field is "MSDP-MIB::msdpPeerState\_10\_10\_11\_90" =\> "1",  
i want the output looks like as below,

"message" =\> "..",  
"host" =\> "10.10.10.13",  
"@version" =\> "1",  
"@timestamp" =\> "2016-04-08T06:22:17.711Z",  
"type" =\> "snmptrap",  
"MSDP-MIB::msdpPeerState\_10\_10\_11\_90" =\> "1",  
"source\_ip" =\> "10.10.10.13"

---

_[View the full topic](https://discuss.elastic.co/t/how-to-remove-dynamical-field/46772)._
