# How to set "enabled":"False" to a field in filebeat

**URL:** <https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 16, 2022, 10:38am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806 "2022-05-16T10:38:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kuo\_Hugo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuo_hugo/32/1641_2.png) [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Post date:** [May 16, 2022, 10:38am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/1 "2022-05-16T10:38:43Z")

</div>

Add it to setup.template.fields file. But the index template doesn't have the "enabled: false" applied.  
Is there a way to disable a field from indexing ?

```auto
  - name: message
    level: core
    type: text
    enabled: false
    description: 'For log events the message field contains the log message'
    example: This is test from Openstack Swift

```

Regards // Hugo

---

<div class="post-metadata">

**Author:** ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Post date:** [May 16, 2022, 11:25am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/2 "2022-05-16T11:25:30Z")

</div>

Hi Hugo,

Welcome to the community.

can you please reformulate your question as it is not clear?

---

<div class="post-metadata">

**Author:** ![Kuo\_Hugo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuo_hugo/32/1641_2.png) [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Post date:** [May 17, 2022, 3:34am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/3 "2022-05-17T03:34:31Z")

</div>

Hi @ibra_013 ,

In the document, there's enabled option for field. There're around 30 fields in out doc. I'd like to disable index for few fields. The doc is sent via Filebeat. I thought there's option for filebeat to create index template with fields disabled.

> **[enabled | Elasticsearch Reference \[6.2\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/enabled.html)**

How to specify enabled: false in Filebeat's fields.yml ?

Thanks // Hugo

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2022, 3:43am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/4 "2022-05-17T03:43:09Z")

</div>

You're linking to Elasticsearch documentation there, so it's not a Filebeat concept you can configure. You need to create your own template that sets this. Alternatively you can just drop the field with Filebeat.

Also 6.X of the stack id [EOL](https://www.elastic.co/support/eol), you need to upgrade.

---

<div class="post-metadata">

**Author:** ![Kuo\_Hugo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuo_hugo/32/1641_2.png) [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Post date:** [May 17, 2022, 7:54am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/5 "2022-05-17T07:54:24Z")

</div>

@warkolm

> Also 6.X of the stack id [EOL](https://www.elastic.co/support/eol), you need to upgrade.  
> Sorry for confusion, we are using 7.4.

> **[Defining field mappings | Beats Developer Guide \[master\] | Elastic](https://www.elastic.co/guide/en/beats/devguide/current/event-fields-yml.html)**

In the Beats document, there're enabled & index mapping parameters.

What's the difference between these two parameters?

Example of my use case :  
There're account, account\_keyword and additional\_info fields in a doc.  
We're looking for ways to store all three fields in ES but not index the account and additional\_info. The goal is when the user searches the account\_keyword, the account and additional\_info are visible but not searchable.

```auto
        },
        "account" : {
          "type" : "text",
          "index" : false,
          "norms" : false
        },
        "account_keyword" : {
          "type" : "keyword",
          "ignore_above" : 1024
        },
        "additional_info" : {
          "type" : "text",
          "index" : false,
          "norms" : false
        },

```

I found three different mapping for an index. Not very sure about which is the right one for the use case. I tested the `index:false` in the filebeat's fields.yml and I can see the result in the above.

```auto
index: false
index: no
enabled: false

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2022, 7:56am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/6 "2022-05-17T07:56:31Z")

</div>

The documentation you linked to is for building your own custom beat, it does not apply to Filebeat sorry.

---

<div class="post-metadata">

**Author:** ![Kuo\_Hugo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuo_hugo/32/1641_2.png) [@Kuo\_Hugo](https://discuss.elastic.co/u/Kuo_Hugo)\
**Post date:** [May 17, 2022, 8:15am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/7 "2022-05-17T08:15:34Z")

</div>

Thanks to point it out. @warkolm I noticed this option in the fields.yaml from package.  
It seems commonly used in filebeat.x86\_64 7.10.2-1

```auto
[root@hkd filebeat]# grep index: fields.yml -B 5
      - name: text
        type: text
        norms: false
        default_field: false
      description: The stack trace of this error in plain text.
      index: false
--
    - name: x509.public_key_exponent
      level: extended
      type: long
      description: Exponent used to derive the public key. This is algorithm specific.
      example: 65537
      index: false
--
    - name: client.x509.public_key_exponent
      level: extended
      type: long
      description: Exponent used to derive the public key. This is algorithm specific.
      example: 65537
      index: false
--
    - name: server.x509.public_key_exponent
      level: extended
      type: long
      description: Exponent used to derive the public key. This is algorithm specific.
      example: 65537
      index: false
--
    - name: public_key_exponent
      level: extended
      type: long
      description: Exponent used to derive the public key. This is algorithm specific.
      example: 65537
      index: false
--
          description: "Server log file"
          type: group
          fields:
          - name: stacktrace
            description": Stack trace in case of errors
            index: false

[root@hkd filebeat]# yum list installed | grep filebeat
filebeat.x86_64 7.10.2-1 @/filebeat-oss-7.10.2-x86_648F6NQU

```

Regards // Hugo

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 10:16am UTC](https://discuss.elastic.co/t/how-to-set-enabled-false-to-a-field-in-filebeat/304806/8 "2022-06-14T10:16:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
