# Logstash is not working - mutate,remove\_field

**URL:** <https://discuss.elastic.co/t/logstash-is-not-working-mutate-remove-field/258852>\
**Category:** Logstash\
**Created:** [December 16, 2020, 11:10am UTC](https://discuss.elastic.co/t/logstash-is-not-working-mutate-remove-field/258852 "2020-12-16T11:10:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![KyungJin\_Joo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kyungjin_joo/32/77246_2.png) [@KyungJin\_Joo](https://discuss.elastic.co/u/KyungJin_Joo)\
**Post date:** [December 16, 2020, 11:10am UTC](https://discuss.elastic.co/t/logstash-is-not-working-mutate-remove-field/258852/1 "2020-12-16T11:10:59Z")

</div>

winlogbeat-my computer  
logstash-(GCP Compute Engine)

Winlogbeat sends sysmon field from logstash.  
Filtering is as follows,  
It was written in a format that maps the ProcessCreate event.

However, writing this way works well.  
---logstash.conf---

```auto
    input {
       beats {
         port => 5044
       }
    }
    filter{
        if([event][code]==1){
            grok{
                match=>{"message"=>'.*?\n?RuleName: (?<RuleName>.+\n).*?UtcTime: (?<UtcTime>.+\n).*?ProcessGuid: (?<ProcessGuid>.+\n).*?ProcessId: (?<ProcessId>.+\n).*?Image: (?<Image>.+\n).*?FileVersion: (?<FileVersion>.+\n).*?Description: (?<Description>.+\n).*?Product: (?<Product>.+\n).*?Company: (?<Company>.+\n).*?OriginalFileName: (?<OriginalFileName>.+\n).*?CommandLine: (?<CommandLine>.+\n).*?CurrentDirectory: (?<CurrentDirectory>.+\n).*?User: (?<User>.+\n).*?LogonGuid: (?<LogonGuid>.+\n).*?LogonId: (?<LogonId>.+\n).*?TerminalSessionId: (?<TerminalSessionId>.+\n).*?IntegrityLevel: (?<IntegrityLevel>.+\n).*?Hashes: (?<Hashes>.+\n).*?ParentProcessGuid: (?<ParentProcessGuid>.+\n).*?ParentProcessId: (?<ParentProcessId>.+\n).*?ParentImage: (?<ParentImage>.+\n).*?ParentCommandLine: (?<ParentCommandLine>.+)'}
            }
        }
    }
    output {
      elasticsearch {
        hosts => ["http://localhost:9200"]
        index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      }
    }

```

If I create a remove\_field, mutate area, it doesn't work.  
Data does not pass from winlogbeat to logstash.

```auto
    input {
       beats {
     port => 5044
       }
    }
    filter{
        if([event][code]==1){
            grok{
                match=>{"message"=>'.*?\n?RuleName: (?<RuleName>.+\n).*?UtcTime: (?<UtcTime>.+\n).*?ProcessGuid: (?<ProcessGuid>.+\n).*?ProcessId: (?<ProcessId>.+\n).*?Image: (?<Image>.+\n).*?FileVersion: (?<FileVersion>.+\n).*?Description: (?<Description>.+\n).*?Product: (?<Product>.+\n).*?Company: (?<Company>.+\n).*?OriginalFileName: (?<OriginalFileName>.+\n).*?CommandLine: (?<CommandLine>.+\n).*?CurrentDirectory: (?<CurrentDirectory>.+\n).*?User: (?<User>.+\n).*?LogonGuid: (?<LogonGuid>.+\n).*?LogonId: (?<LogonId>.+\n).*?TerminalSessionId: (?<TerminalSessionId>.+\n).*?IntegrityLevel: (?<IntegrityLevel>.+\n).*?Hashes: (?<Hashes>.+\n).*?ParentProcessGuid: (?<ParentProcessGuid>.+\n).*?ParentProcessId: (?<ParentProcessId>.+\n).*?ParentImage: (?<ParentImage>.+\n).*?ParentCommandLine: (?<ParentCommandLine>.+)'}
            }
            mutate {
             convert => {
               "RuleName" => "text"
               "UtcTime" => "text"
               "ProcessGuid" => "text"
               "ProcessId" => "text"
               "Image" => "text"
               "FileVersion" => "text"
               "Description" => "text"
               "Product" => "text"
               "Company" => "text"
               "OriginalFileName" => "text"
               "CommandLine" => "text"
               "CurrentDirectory" => "text"
               "User" => "text"
               "LogonGuid" => "text"
               "TerminalSessionId" => "text"
               "IntegrityLevel" => "text"
               "ParentProcessGuid" => "text"
               "Hashes" => "text"
               "ParentProcessId" => "text"
               "ParentImage" => "text"
               "ParentCommandLine" => "text"
              }
              remove_field => ["message"]
            }
        }
    }
    output {
      elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      }
    }

```

Could you solve it?

ps: I check vaild use bin/logstash --config.test\_and\_exit -f /etc/logstash/conf.d/logstash.conf

This has passed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2021, 11:11am UTC](https://discuss.elastic.co/t/logstash-is-not-working-mutate-remove-field/258852/2 "2021-01-13T11:11:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
