# How to remove fields with - values in logstash filter?

**URL:** <https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879>\
**Category:** Logstash\
**Created:** [December 3, 2021, 11:31am UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879 "2021-12-03T11:31:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anusha\_Kusanghi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anusha_kusanghi/32/98109_2.png) [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Post date:** [December 3, 2021, 11:31am UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879/1 "2021-12-03T11:31:39Z")

</div>

I have a patterns like :

1. 2021-10-15 20:00:13 2396 tstur1 /ftp/workspace/ this is message
2. 2020-10-15 18:00:13 - - this is the second message  
The fields are Date, Time, SessionId, path and message.  
The grok pattern used is :  
`%{DATE:date} %{TIME:time} %{DATA:sessionid} %{DATA:username} %{DATA:path} %{GREEDYDATA:message}`

is it possible to do a dynamic filter in logstash that will remove any fields with - value?

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [December 3, 2021, 4:39pm UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879/2 "2021-12-03T16:39:29Z")

</div>

Absolutely!  
After your grok statement you can write an if statement.

```auto
if [sessionid] == "-" {
   mutate {
      remove_field => ["sessionid"]
   }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 3, 2021, 7:13pm UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879/3 "2021-12-03T19:13:53Z")

</div>

Another possible solution is a prune filter with the [blacklist\_values](https://www.elastic.co/guide/en/logstash/current/plugins-filters-prune.html#plugins-filters-prune-blacklist_values) options.

---

<div class="post-metadata">

**Author:** ![Anusha\_Kusanghi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anusha_kusanghi/32/98109_2.png) [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Post date:** [December 6, 2021, 9:58am UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879/4 "2021-12-06T09:58:09Z")

</div>

thank you @AquaX for the help

---

<div class="post-metadata">

**Author:** ![Anusha\_Kusanghi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anusha_kusanghi/32/98109_2.png) [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Post date:** [December 6, 2021, 9:58am UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879/5 "2021-12-06T09:58:35Z")

</div>

thank you @Badger it worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2022, 9:59am UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879/6 "2022-01-03T09:59:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
