# Logstash output syslog : how to remove added {host} field?

**URL:** <https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246>\
**Category:** Logstash\
**Created:** [January 5, 2021, 5:11pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246 "2021-01-05T17:11:36Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [January 6, 2021, 5:14pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/4 "2021-01-06T17:14:04Z")

</div>

As reported here -\> [Logstash syslog output ignores message](https://discuss.elastic.co/t/logstash-syslog-output-ignores-message/220434) it looks like there is like a bug and the workaround is to add the field "host" in filter to be taken into account by the plugin

So, for my needs I use this :

```
#keep only message of log and add empty host field
filter
{
prune {
  whitelist_names => ["^message$"]
  }
mutate {
  add_field => {"host" => ""}
  }
}

```

This way, received log by syslog relay is :

> \<13\> Jan 5 16:42:29 server1 misc-centreon(misc\_centreon)[61665]: INFO: running

Unfortunately, as you can see, there i still a space after \<13\> but it's already that !

I don't understand why it is so hard to find where does comes from this %{host} field. If someone has a better comprehension... 😉

---

_[View the full topic](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246)._
