# Http filter leaves fields, that are inserted to elasticsearch

**URL:** <https://discuss.elastic.co/t/http-filter-leaves-fields-that-are-inserted-to-elasticsearch/200470>\
**Category:** Logstash\
**Created:** [September 20, 2019, 5:28pm UTC](https://discuss.elastic.co/t/http-filter-leaves-fields-that-are-inserted-to-elasticsearch/200470 "2019-09-20T17:28:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 20, 2019, 5:28pm UTC](https://discuss.elastic.co/t/http-filter-leaves-fields-that-are-inserted-to-elasticsearch/200470/1 "2019-09-20T17:28:33Z")

</div>

Basically my pipeline looks like this:

```auto
input {
    (...) #some input
}
filter {
    http {
        (...) #http request
    }
}
output{
    elasticsearch{
        (...)
        action => "update"
        doc_as_upsert => true
    }
}

```

I need http filter to do a particular HTTP request. But nothing more in http filter, I am not reading data back.  
Usage of that filter unwanted result is, that fields produced by http filter are being inserted into ELS document which is updated. For example: `headers`, `body`, `@version`, `@timestamp`, ...  
I tried to use `mutate` with `remove_field` to get rid of those unnecessary fields, which work for  
`headers` and `body`, but I am left with fields like `@version`, `@timestamp` which I cannot remove (document will not be updated in ELS) but also do not want them in my document `_source`.  
Is there a way to perform http filter without adding new fields to the event?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 20, 2019, 5:39pm UTC](https://discuss.elastic.co/t/http-filter-leaves-fields-that-are-inserted-to-elasticsearch/200470/2 "2019-09-20T17:39:44Z")

</div>

@version and @timestamp are not added by the http filter. They are added to all events by logstash. If I recall correctly @timestamp is mandatory, elasticsearch requires it to be present. Not sure about @version.

---

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 20, 2019, 6:11pm UTC](https://discuss.elastic.co/t/http-filter-leaves-fields-that-are-inserted-to-elasticsearch/200470/3 "2019-09-20T18:11:52Z")

</div>

Yes, my mistake.  
I would delete this topic, but I do not have permission to do so.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2019, 6:11pm UTC](https://discuss.elastic.co/t/http-filter-leaves-fields-that-are-inserted-to-elasticsearch/200470/4 "2019-10-18T18:11:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
