# Logstash Remove help

**URL:** <https://discuss.elastic.co/t/logstash-remove-help/2468>\
**Category:** Logstash\
**Created:** [June 11, 2015, 1:20pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468 "2015-06-11T13:20:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 11, 2015, 1:20pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/1 "2015-06-11T13:20:47Z")

</div>

I pull in the twitter json and want to remove certain fields from the user. object as well as some other fields. I cannot get it to work.

here is my filter:

filter {  
if [field] =~ /in\_reply\_to\*/ {  
json {  
source =\> "message"  
remove\_field =\> [field]  
}  
}  
if [field] =~ /user.profile\*/ {  
json {  
source =\> "message"  
target =\> "user"  
remove\_field =\> [field]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2015, 1:57pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/2 "2015-06-11T13:57:53Z")

</div>

Double-quote the field name:

```
json {
  ...
  remove_field => ["field"]
}
```

---

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 11, 2015, 2:16pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/3 "2015-06-11T14:16:51Z")

</div>

What I am trying to do is to remove any field that starts with "in\_reply\_to". even after double quoting, it does not work.

---

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 11, 2015, 2:22pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/4 "2015-06-11T14:22:15Z")

</div>

Here is a sample json. I want to remove anything with in\_reply\_to\* as well as user.timezone field. how can I do it?

{  
"\_index": "twitter",  
"\_type": "tweet",  
"\_id": "AU3i9z7NNs7nuNHjMvVu",  
"\_score": null,  
"\_source": {  
"created\_at": "Thu Jun 11 14:12:43 +0000 2015",  
"id": 609000309688574000,  
"id\_str": "609000309688573952",  
"text": "RT @Nesrin\_ulema: ",  
"source": "\<a href="http://twitter.com/download/android" rel="nofollow"\>Twitter for Android",  
"truncated": false,  
"in\_reply\_to\_status\_id": null,  
"in\_reply\_to\_status\_id\_str": null,  
"in\_reply\_to\_user\_id": null,  
"in\_reply\_to\_user\_id\_str": null,  
"in\_reply\_to\_screen\_name": null,  
"user": {  
"id": 2187249188,  
"id\_str": "2187249188",  
"name": "Ayşe Arabacı",  
"screen\_name": "AyseArabacii",  
"location": "",  
"url": null,  
"description": "",  
"protected": false,  
"verified": false,  
"followers\_count": 452,  
"friends\_count": 609,  
"listed\_count": 3,  
"favourites\_count": 1154,  
"statuses\_count": 6615,  
"created\_at": "Sun Nov 10 22:12:53 +0000 2013",  
"utc\_offset": null,  
"time\_zone": null,  
"geo\_enabled": true,  
"lang": "tr",  
"contributors\_enabled": false,  
"is\_translator": false,  
"profile\_background\_color": "C0DEED",  
"profile\_background\_image\_url": "http://abs.twimg.com/images/themes/theme1/bg.png",  
"profile\_background\_image\_url\_https": "https://abs.twimg.com/images/themes/theme1/bg.png",  
"profile\_background\_tile": false,  
"profile\_link\_color": "0084B4",  
"profile\_sidebar\_border\_color": "C0DEED",  
"profile\_sidebar\_fill\_color": "DDEEF6",  
"profile\_text\_color": "333333",  
"profile\_use\_background\_image": true,  
"profile\_image\_url": "http://pbs.twimg.com/profile\_images/594269698004484097/rOEI46FR\_normal.jpg",  
"profile\_image\_url\_https": "https://pbs.twimg.com/profile\_images/594269698004484097/rOEI46FR\_normal.jpg",  
"default\_profile": true,  
"default\_profile\_image": false,  
"following": null,  
"follow\_request\_sent": null,  
"notifications": null  
},  
"geo": null,  
"coordinates": null,  
"place": null,  
"contributors": null,  
"retweeted\_status": {  
"created\_at": "Thu Jun 11 08:18:28 +0000 2015",  
"id": 608911160432296000,  
"id\_str": "608911160432295936",  
"text": "Sayın Başbakanımız ",  
"source": "\<a href="http://twitter.com/download/android" rel="nofollow"\>Twitter for Android",  
"truncated": false,  
"in\_reply\_to\_status\_id": null,  
"in\_reply\_to\_status\_id\_str": null,  
"in\_reply\_to\_user\_id": null,  
"in\_reply\_to\_user\_id\_str": null,  
"in\_reply\_to\_screen\_name": null,  
"user": {  
"id": 387303168,  
"id\_str": "387303168",  
"name": "Nesrin ULEMA",  
"screen\_name": "Nesrin\_ulema",  
"location": "İzmir / Ankara",  
"url": null,  
"description": "",  
"protected": false,  
"verified": false,  
"followers\_count": 7025,  
"friends\_count": 337,  
"listed\_count": 60,  
"favourites\_count": 186,  
"statuses\_count": 5495,  
"created\_at": "Sat Oct 08 20:25:51 +0000 2011",  
"utc\_offset": 10800,  
"time\_zone": "Istanbul",  
"geo\_enabled": true,  
"lang": "tr",  
"contributors\_enabled": false,  
"is\_translator": false,  
"profile\_background\_color": "C0DEED",  
"profile\_background\_image\_url": "[http://abs.twimg.com/images/themes/theme1/bg.png](http://abs.twimg.com/images/themes/theme1/bg.png)",  
"profile\_background\_image\_url\_https": "[https://abs.twimg.com/images/themes/theme1/bg.png](https://abs.twimg.com/images/themes/theme1/bg.png)",  
"profile\_background\_tile": false,  
"profile\_link\_color": "0084B4",  
"profile\_sidebar\_border\_color": "C0DEED",  
"profile\_sidebar\_fill\_color": "DDEEF6",  
"profile\_text\_color": "333333",  
"profile\_use\_background\_image": true,  
"profile\_image\_url": "[http://pbs.twimg.com/profile\_images/569595885521477633/Fi18kf4J\_normal.jpeg](http://pbs.twimg.com/profile_images/569595885521477633/Fi18kf4J_normal.jpeg)",  
"profile\_image\_url\_https": "[https://pbs.twimg.com/profile\_images/569595885521477633/Fi18kf4J\_normal.jpeg](https://pbs.twimg.com/profile_images/569595885521477633/Fi18kf4J_normal.jpeg)",  
"profile\_banner\_url": "[https://pbs.twimg.com/profile\_banners/387303168/1433104916](https://pbs.twimg.com/profile_banners/387303168/1433104916)",  
"default\_profile": true,  
"default\_profile\_image": false,  
"following": null,  
"follow\_request\_sent": null,  
"notifications": null  
},  
"geo": null,  
"coordinates": null,  
"place": null,  
"contributors": null,  
"retweet\_count": 27,  
"favorite\_count": 18,  
"entities": {  
"hashtags": [],  
"trends": [],  
"urls": [],  
"user\_mentions": [],  
"symbols": []  
},  
"favorited": false,  
"retweeted": false,  
"possibly\_sensitive": true,  
"filter\_level": "low",  
"lang": "tr"  
},  
"retweet\_count": 0,  
"favorite\_count": 0,  
"entities": {  
"hashtags": [],  
"trends": [],  
"urls": [],  
"user\_mentions": [  
{  
"screen\_name": "Nesrin\_ulema",  
"name": "Nesrin ULEMA",  
"id": 387303168,  
"id\_str": "387303168",  
"indices": [  
3,  
16  
]  
}  
],  
"symbols": []  
},  
"favorited": false,  
"retweeted": false,  
"possibly\_sensitive": false,  
"filter\_level": "low",  
"lang": "tr",  
"timestamp\_ms": "1434031963165",  
"@version": "1",  
"@timestamp": "2015-06-11T14:12:43.000Z"  
},  
"fields": {  
"text": [  
"RT @Nesrin\_ulema: "  
],  
"@timestamp": [  
1434031963000  
]  
},  
"sort": [  
1434031963000  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2015, 5:22pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/5 "2015-06-11T17:22:38Z")

</div>

Okay. `remove_field` doesn't support wildcards so you'll have to use a [ruby filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html). Untested:

```
filter {
  ruby {
    code => "
      event.to_hash.keys.each { |k|
        event.remove(k) if k.start_with?('in_reply_to_')
      }
    "
  }
}

```

---

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 11, 2015, 5:50pm UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/6 "2015-06-11T17:50:39Z")

</div>

Awesome. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-remove-help/2468/7 "2017-07-06T05:37:39Z")

</div>


