# Redundant fields in elsatic

**URL:** <https://discuss.elastic.co/t/redundant-fields-in-elsatic/117066>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 25, 2018, 3:34pm UTC](https://discuss.elastic.co/t/redundant-fields-in-elsatic/117066 "2018-01-25T15:34:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![80c1141eb6d0c564dd90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/80c1141eb6d0c564dd90/32/20893_2.png) [@80c1141eb6d0c564dd90](https://discuss.elastic.co/u/80c1141eb6d0c564dd90)\
**Post date:** [January 25, 2018, 3:34pm UTC](https://discuss.elastic.co/t/redundant-fields-in-elsatic/117066/1 "2018-01-25T15:34:48Z")

</div>

I have redundant field in Kibana, what can I make not to show them?  
Fields are like

```
"beat": {
  "hostname": "preprod-api.example.com", <-- (host, where from logs go to logstash)
  "name": "preprod-api.example.com",
  "version": "6.1.0"
},
"preprod-api.example.com": "",
"prospector": {
  "type": "log"
},

```

I have this settings for template in /etc/filebeat/filebeat.yml:

setup.template.enabled: true  
[setup.template.name](http://setup.template.name): "preprod-filebeat-%{+YYYY.MM.dd}"  
setup.template.pattern: "preprod-filebeat-\*"  
setup.template.fields: "/etc/filebeat/fields.yml"  
setup.template.overwrite: true

and this is /etc/filebeat/fields.yml:

- key: log  
title: Log file content  
description: \>  
Contains log file lines.  
fields:
  - name: source  
type: keyword  
required: true  
description: \>  
The file from which the line was read. This field contains the absolute path to the file.  
For example: `/var/log/system.log`.

  - name: message  
type: text  
ignore\_above: 0  
required: true  
description: \>  
The content of the line read from the log file.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 25, 2018, 3:56pm UTC](https://discuss.elastic.co/t/redundant-fields-in-elsatic/117066/2 "2018-01-25T15:56:59Z")

</div>

If you don't want the fields in Kibana then configure the source to not send them.

In Beats this can be don't by using the [drop\_field processor](https://www.elastic.co/guide/en/beats/filebeat/6.1/drop-fields.html). Put this into you filebeat.yml and restart.

```auto
processors:
- drop_fields:
    fields:
    - beat.hostname
    - <other fields to drop>

```

No changes are required to the `fields.yml`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2018, 3:57pm UTC](https://discuss.elastic.co/t/redundant-fields-in-elsatic/117066/3 "2018-02-22T15:57:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
