# Ingest pipeline, "remove" nested fields

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-remove-nested-fields/283989>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [September 12, 2021, 8:09pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-nested-fields/283989 "2021-09-12T20:09:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [September 12, 2021, 8:09pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-nested-fields/283989/1 "2021-09-12T20:09:18Z")

</div>

Version 7.14

I am attempting to filter a winlogbeats stream in an ingest pipeline. One thing I want to do is strip out the whole agent tree as this is repeated in every record.

Is there a way to remove "agent.\*" in one go?

Aside: it is also unclear to me if these field are "flattened" (i.e. do I need to use dot expander) and how would I know.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 12, 2021, 8:57pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-nested-fields/283989/2 "2021-09-12T20:57:06Z")

</div>

Technically I believe the agent fields has sub-objects and is not nested.  
See [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/object.html)

You do not need the dotexpander and you can just name the top field in your case `agent` if you completely want to remove the whole `agent` tree

```auto
PUT /_ingest/pipeline/test-remove
{
  "processors" : [
    {
      "remove": {
        "field": "field-b"
      }
    }
  ]
}

# This is how you simulated a pipeline
POST /_ingest/pipeline/test-remove/_simulate
{
  "docs": [
    {
      "_index": "index",
      "_id": "id",
      "_source": {
        "field-a": "1234",
        "field-b":
        {
          "sub1" : "value1",
          "sub2" : "value2"
        }
      }
    }
  ]
}

```

results note entire `field-b` is removed

```auto
{
  "docs" : [
    {
      "doc" : {
        "_index" : "index",
        "_type" : "_doc",
        "_id" : "id",
        "_source" : {
          "field-a" : "1234"
        },
        "_ingest" : {
          "timestamp" : "2021-09-12T20:54:48.4217817Z"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [September 13, 2021, 7:50pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-nested-fields/283989/3 "2021-09-13T19:50:54Z")

</div>

Thanks! that is exactly what I needed.  
works as advertised : )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2021, 7:51pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-nested-fields/283989/4 "2021-10-11T19:51:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
