# Not to add 'host', 'path' field

**URL:** <https://discuss.elastic.co/t/not-to-add-host-path-field/49889>\
**Category:** Logstash\
**Created:** [May 12, 2016, 11:20am UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889 "2016-05-12T11:20:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![no\_jihun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/no_jihun/32/64028_2.png) [@no\_jihun](https://discuss.elastic.co/u/no_jihun)\
**Post date:** [May 12, 2016, 11:20am UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889/1 "2016-05-12T11:20:40Z")

</div>

Hi.

With this configuration,

```auto
input {
    file {
        path => ...
    }
}
output {
    elasticsearch {
        ...
    }
}

```

logstash add files 'host' and 'path' to the document.

```auto
  "_source": {
   ...
    "path": "/home1/.logstash/input/default_agg_daily/0505.json",
    "host": "xyzzzz"
  },

```

And I want to remove path and host by

```auto
mutate {remove_fileds => [...] }

```

But some case the origin document may contain field 'path' and/or 'host'.  
So I can not use remove\_filds simply.

Is there a way make logstash not to add 'host' and 'path' field?

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 12, 2016, 11:47am UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889/2 "2016-05-12T11:47:00Z")

</div>

The right configuration is :

```
mutate {
  remove_field => ["path", "host"]
}

```

And for information, if field path and/or host doesn't exist, there's no problem. The plugin will remove field if field exists, and just do nothing if field does not exist.

---

<div class="post-metadata">

**Author:** ![no\_jihun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/no_jihun/32/64028_2.png) [@no\_jihun](https://discuss.elastic.co/u/no_jihun)\
**Post date:** [May 12, 2016, 12:06pm UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889/3 "2016-05-12T12:06:37Z")

</div>

thanks!

but I knows remove fields only works when that fields exist.

the problem is  
some of input of fileinputplugin contains host field.  
in that case logstash will not add/overwrite host field.

but when origin input does not have host field it will add hist field.

in short  
I want logstash not to add host field by itself.

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 12, 2016, 12:28pm UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889/4 "2016-05-12T12:28:19Z")

</div>

OK, so I suppose your file input plugin use "json" codec ?  
I mean, if it reads plain lines, there is no "host" field in input of file input plugin.

Presently, there is no way to disable "host" field in file input plugin.

You could open an issue for that :

> **[logstash-plugins/logstash-input-file](https://github.com/logstash-plugins/logstash-input-file/issues)**
>
> Contribute to logstash-input-file development by creating an account on GitHub.

And otherwise, you can use a trick :

- read file with plain codec
- then use mutate filter to remove "host" and "path" fields
- then use "json" filter to convert message field to json document

---

<div class="post-metadata">

**Author:** ![no\_jihun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/no_jihun/32/64028_2.png) [@no\_jihun](https://discuss.elastic.co/u/no_jihun)\
**Post date:** [May 12, 2016, 2:52pm UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889/5 "2016-05-12T14:52:21Z")

</div>

Thank you for the clear response.

You are right.  
input file configured as json codec.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:57am UTC](https://discuss.elastic.co/t/not-to-add-host-path-field/49889/6 "2017-07-06T04:57:51Z")

</div>


