# Remove fields from documents based on their value

**URL:** <https://discuss.elastic.co/t/remove-fields-from-documents-based-on-their-value/200270>\
**Category:** Logstash\
**Created:** [September 19, 2019, 4:37pm UTC](https://discuss.elastic.co/t/remove-fields-from-documents-based-on-their-value/200270 "2019-09-19T16:37:16Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 19, 2019, 6:29pm UTC](https://discuss.elastic.co/t/remove-fields-from-documents-based-on-their-value/200270/7 "2019-09-19T18:29:33Z")

</div>

I have request, that works in Kibana console:

> POST test\_idx1/\_update/1  
> {  
> "script" : "ctx.\_source.remove('field1')"  
> }

I copied it as cURL:

> curl -XPOST "[http://localhost:9200/test\_idx1/\_update/1](http://localhost:9200/test_idx1/_update/1)" -H 'Content-Type: application/json' -d'{ "script" : "ctx.\_source.remove("field1")"}'

From which I tried to do deduct HTTP filter:

> filter {  
> http {  
> url =\> "[http://localhost:9200/test\_idx1/\_update/1](http://localhost:9200/test_idx1/_update/1)"  
> verb =\> "POST"  
> user =\> "logstash\_user"  
> password =\> "logstash\_user\_password"  
> body\_format =\> "json"  
> body =\> "{\"script\" : \"ctx.\_source.remove(\\\"field1\\\")\"}"  
> }  
> }

After running Logstash no error is logged, even on DEBUG level. No update is happening in Elasticsearch.  
What am I missing?

---

_[View the full topic](https://discuss.elastic.co/t/remove-fields-from-documents-based-on-their-value/200270)._
