# Logstash query against elastic returning unwanted field

**URL:** <https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [April 5, 2023, 11:01am UTC](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418 "2023-04-05T11:01:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Post date:** [April 5, 2023, 11:01am UTC](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418/1 "2023-04-05T11:01:56Z")

</div>

I am exporting the metricbeat index from elastic using logstash.

I would like to exclude the `service.type` term `docker` from the output. I am using the following query:

```auto
            query => '{
                "query": {
                  "bool": {
                    "should":[{"term":{"service.type":"kubernetes"}},{"term":{"service.type":"prometheus"}},{"term":{"service.type":"system"}}],
                    "filter": [{"range": { "@timestamp": {"gte": "now-15m","lte": "now","format": "strict_date_optional_time||epoch_millis"}}}]
                  }
              }
            }'

```

So, the query above I am just including the service types that I want to see in the output index. However, in the resulting json output file, I am still seeing the service type docker.

```auto
    "max_score" : 0.8040674,
    "hits" : [
      {
        "_index" : "metricbeat-7.17.7-2023.04.04-000007",
        "_type" : "_doc",
        "_id" : "t4NRUIcBtJJ8K_62Ehkk",
        "_score" : 0.8040674,
        "_source" : {
          "@version" : "1",
          "service" : {
            "address" : "unix:///var/run/docker.sock",
            "type" : "docker"
          },

```

---

<div class="post-metadata">

**Author:** ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)\
**Post date:** [April 6, 2023, 5:05am UTC](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418/2 "2023-04-06T05:05:45Z")

</div>

using the should clause for the `service.type` terms means it will return documents that match any of the listed terms but does not exclude the "docker" service type. elastic docs: [Boolean query | Elasticsearch Guide [7.17] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/query-dsl-bool-query.html)

Please try and modify the query to include a `must_not` clause inside the `bool` query to exclude the docker `service type`

something like this...

```auto
      "must_not": [
        {"term": {"service.type": "docker"}}
      ],

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2023, 5:06am UTC](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418/3 "2023-05-04T05:06:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
