# Logstash mutate filter

**URL:** <https://discuss.elastic.co/t/logstash-mutate-filter/59978>\
**Category:** Logstash\
**Created:** [September 7, 2016, 12:23pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978 "2016-09-07T12:23:04Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![TRSRaphael](https://avatars.discourse-cdn.com/v4/letter/t/3e96dc/32.png) [@TRSRaphael](https://discuss.elastic.co/u/TRSRaphael)\
**Post date:** [September 7, 2016, 12:23pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/1 "2016-09-07T12:23:05Z")

</div>

Hello,

logstash is getting the events coming from collectd and put it in ElasticSearch.

from kibana (plugged on ElasticSearch) I see the logstash index fields : geoip.ip, geoip.location, majflt, ...

In the input-collectd.conf file I defined a filter to remove some useless fields.  
This is the filter:

filter {  
mutate {  
remove\_field =\> ["[geoip][ip]", "majflt" ]  
}  
}

This configuration file is correct. The "majflt" field is removed as expected but I still see the "geoip.ip" field. Does someone know the explanation ?

Regards,  
Raphaël

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 7, 2016, 1:22pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/2 "2016-09-07T13:22:09Z")

</div>

Works fine for me with Logstash 2.3.2:

```nohighlight
$ cat test.config 
input { stdin { codec => json } }
output { stdout { codec => rubydebug } }
filter {
  mutate {
    remove_field => ["[geoip][ip]", "majflt" ]
  }
}
$ echo '{"geoip": {"ip": "1.2.3.4"}, "majflt": "foo"}' | /opt/logstash/bin/logstash -f test.config 
Settings: Default pipeline workers: 8
Pipeline main started
{
         "geoip" => {},
      "@version" => "1",
    "@timestamp" => "2016-09-07T13:21:16.736Z",
          "host" => "lnxolofon"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![TRSRaphael](https://avatars.discourse-cdn.com/v4/letter/t/3e96dc/32.png) [@TRSRaphael](https://discuss.elastic.co/u/TRSRaphael)\
**Post date:** [September 7, 2016, 2:23pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/3 "2016-09-07T14:23:27Z")

</div>

I did the same test as you and it works also (with 2.3.2 version).

With the following configuration files I always see geoip.ip in Kibana :

# more input-collectd.conf

input {  
udp {  
port =\> 25826  
buffer\_size =\> 1452  
codec =\> collectd { }  
}  
}  
filter {  
mutate {  
remove\_field =\> ["[geoip][ip]", "majflt", "threads" ]  
}  
}

# more output-elasticsearch.conf

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
}  
filter {  
mutate {  
remove\_field =\> ["[geoip][ip]", "majflt", "threads" ]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 8, 2016, 5:28am UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/4 "2016-09-08T05:28:07Z")

</div>

Please replace the elasticsearch output with a `stdout { codec => rubydebug }` output so we can see exactly what happens.

---

<div class="post-metadata">

**Author:** ![TRSRaphael](https://avatars.discourse-cdn.com/v4/letter/t/3e96dc/32.png) [@TRSRaphael](https://discuss.elastic.co/u/TRSRaphael)\
**Post date:** [September 8, 2016, 4:33pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/5 "2016-09-08T16:33:53Z")

</div>

I did what you said I don't see any geoip in the output file.  
Maybe geoip is integrated with logstash ? I see that a "geoip" filter exists...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 8, 2016, 6:39pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/6 "2016-09-08T18:39:06Z")

</div>

> I did what you said I don't see any geoip in the output file.

Please show us. Do not describe in words what you can describe with a log snippet or something real that can't be misunderstood.

---

<div class="post-metadata">

**Author:** ![TRSRaphael](https://avatars.discourse-cdn.com/v4/letter/t/3e96dc/32.png) [@TRSRaphael](https://discuss.elastic.co/u/TRSRaphael)\
**Post date:** [September 9, 2016, 4:31pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/7 "2016-09-09T16:31:53Z")

</div>

I cannot send the output because it is classified...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2016, 12:20pm UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/8 "2016-09-10T12:20:36Z")

</div>

Yes, but you can obfuscate the data by replacing the pieces that are sensitive.

---

<div class="post-metadata">

**Author:** ![TRSRaphael](https://avatars.discourse-cdn.com/v4/letter/t/3e96dc/32.png) [@TRSRaphael](https://discuss.elastic.co/u/TRSRaphael)\
**Post date:** [September 12, 2016, 8:34am UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/9 "2016-09-12T08:34:15Z")

</div>

As it is classified I just cannot export it (even if there is no sensitive data) ...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:39am UTC](https://discuss.elastic.co/t/logstash-mutate-filter/59978/10 "2017-07-06T04:39:00Z")

</div>


