# Remove\_fields doesn't remove field in json

**URL:** <https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176>\
**Category:** Logstash\
**Created:** [September 26, 2022, 1:55pm UTC](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176 "2022-09-26T13:55:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kostyantyn\_Dobriohlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kostyantyn_dobriohlo/32/104458_2.png) [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Post date:** [September 26, 2022, 1:55pm UTC](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176/1 "2022-09-26T13:55:30Z")

</div>

Cannot remove fields in json, 'cause always have a json parsing error. Tried many different ways, but inside the json nothing changes. And there is a warning in logs: Error parsing json

Config file:

```auto
input {
  tcp {
    port => 5959
    codec => json {
      target => "extra"
    }
  }
}
filter {
  json {
    source => "extra"
    remove_field => ["line"]
  }
  mutate {
    remove_field => ["message", "program", "host", "logsource"]
  }
}
output {
  elasticsearch {
    hosts => ["http://elasticsearch:9200"]
    index => "log-stash"
  }
}

```

Warning message:

```auto
logstash_1 | [WARN] 2022-09-26 13:44:40.745 [[main]>worker4] json - Error parsing json {:source=>"extra", :raw=>{"interpreter_version"=>"3.9.2", "interpreter"=>"C:\\Users\\Kostya\\Desktop\\Работа\\testShit\\Scripts\\python.exe", "logger_name"=>"test", "path"=>"/21", "func_name"=>"log_to_file", "client"=>"127.0.0.1", "line"=>96, "status"=>400, "logstash_async_version"=>"2.5.0", "params"=>{"pk"=>"21"}, "time"=>"2022-09-26T13:44:29.000Z", "method"=>"GET", "process_name"=>"SpawnProcess-1", "thread_name"=>"MainThread"}, :exception=>#<Java::JavaLang::ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO (org.jruby.RubyHash and org.jruby.RubyIO are in unnamed module of loader 'app')>}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 26, 2022, 4:28pm UTC](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176/2 "2022-09-26T16:28:09Z")

</div>

Hi @Kostyantyn_Dobriohlo Welcome to the community!

> [@Kostyantyn\_Dobriohlo](#):
>
> `{"interpreter_version"=>"3.9.2", "interpreter"=>"C:\\Users\\Kostya\\Desktop\\Работа\\testShit\\Scripts\\python.exe", `

That does not look like valid json to me... `=>` is not valid json so whatever is writing that log line is not writing valid json.

it would be

`{"interpreter_version" : "3.9.2", "interpreter" : "C:\\Users\\Kostya\\Desktop\\Работа\\testShit\\Scripts\\python.exe", `

Can you show a couple raw lines of your logs?

EDIT Ohh Good Eyes @Badger I did not see the first codec! Was wondering why it already looked "logstash-ized" !!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 26, 2022, 4:53pm UTC](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176/3 "2022-09-26T16:53:23Z")

</div>

@Kostyantyn_Dobriohlo you have already parsed the json using the codec, there is no need for a json filter.

```
input { generator { count => 1 lines => ['{ "a": 1, "b": 2 }'] codec => json { target => "extra" } } }
filter { json { source => "extra" remove_field => ["line"] } }
output { stdout { codec => rubydebug { metadata => false } } }

```

will produce the error

```
 Error parsing json {:source=>"extra", :raw=>{"a"=>1, "b"=>2},

```

because [extra] is a hash, not a string.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2022, 4:54pm UTC](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176/4 "2022-10-24T16:54:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
