logstash is getting the events coming from collectd and put it in ElasticSearch.
from kibana (plugged on ElasticSearch) I see the logstash index fields : geoip.ip, geoip.location, majflt, ...
In the input-collectd.conf file I defined a filter to remove some useless fields.
This is the filter:
remove_field => [ "[geoip][ip]", "majflt" ]
This configuration file is correct. The "majflt" field is removed as expected but I still see the "geoip.ip" field. Does someone know the explanation ?