# How to remove empty fields from filebeat-8.15.1

**URL:** <https://discuss.elastic.co/t/how-to-remove-empty-fields-from-filebeat-8-15-1/369353>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 24, 2024, 11:26am UTC](https://discuss.elastic.co/t/how-to-remove-empty-fields-from-filebeat-8-15-1/369353 "2024-10-24T11:26:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahuldastidar](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@rahuldastidar](https://discuss.elastic.co/u/rahuldastidar)\
**Post date:** [October 24, 2024, 11:26am UTC](https://discuss.elastic.co/t/how-to-remove-empty-fields-from-filebeat-8-15-1/369353/1 "2024-10-24T11:26:07Z")

</div>

I have installed and configured filebeat-8.15 on Windows 2019 host, and in the Kibana 'Discover' section in the , customized 'Data Views' which I have created by editing "Index Template" , and dropping the unwanted empty fields , I am getting

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8a57c69a803df076c197612ba3db884ec13c35d.png)  
BTW, I have also created the an ingest pipeline --\>

```auto
[
  {
    "script": {
      "source": " for (entry in ctx.entrySet()) { if (entry.value instanceof String && entry.value.trim().length() == 0) { ctx.remove(entry.key); } } "
    }
  }
]

```

And load it in filebeat.yml --\>

```auto
output.elasticsearch:
  hosts: ["https://<host_ip>:9200"]
  username: "elastic"
  password: "***"
  pipeline: "remove_empty_fields"
  ssl:
    enabled: true
    verification_mode: none

```

But still not able to get rid of the empty fields, is there really a way to omit 6558 number of empty fields? Please let me know

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 24, 2024, 11:44pm UTC](https://discuss.elastic.co/t/how-to-remove-empty-fields-from-filebeat-8-15-1/369353/3 "2024-10-24T23:44:01Z")

</div>

Does this Kibana data view only match this index?

Do the templates that defined this index define these fields?

How old is this index?

---

<div class="post-metadata">

**Author:** ![rahuldastidar](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@rahuldastidar](https://discuss.elastic.co/u/rahuldastidar)\
**Post date:** [October 25, 2024, 5:06pm UTC](https://discuss.elastic.co/t/how-to-remove-empty-fields-from-filebeat-8-15-1/369353/4 "2024-10-25T17:06:34Z")

</div>

Hi @rugenl  
Thanks for your response.  
On your question,

1. Yes  
2)Yes  
3)Contains last 180 days data.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 25, 2024, 5:52pm UTC](https://discuss.elastic.co/t/how-to-remove-empty-fields-from-filebeat-8-15-1/369353/5 "2024-10-25T17:52:47Z")

</div>

If your template defines these fields, but they don't contain data, (I think in any events in the Kibana range, in this case last 15 minutes) they appear as "empty fields".

If the fields never exist, don't map them.

Maybe similar to this: [Mapping explosion | Elasticsearch Guide [8.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-explosion.html)
