# Remove fields on windows event log

**URL:** <https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891>\
**Category:** Logstash\
**Created:** [May 24, 2017, 4:56am UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891 "2017-05-24T04:56:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tharu85](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@tharu85](https://discuss.elastic.co/u/tharu85)\
**Post date:** [May 24, 2017, 4:56am UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/1 "2017-05-24T04:56:37Z")

</div>

{  
"message" =\> "The Windows Filtering Platform has permitted a connection......bla bla.....",  
"@version" =\> "1",  
"@timestamp" =\> "2017-05-24T03:38:00.775Z",  
"type" =\> "wineventlog",  
"task" =\> "Filtering Platform Connection",  
"log\_name" =\> "Security",  
"event\_data" =\> {  
"ProcessID" =\> "860",  
"DestAddress" =\> "192.168.1.1",  
"FilterRTID" =\> "0",  
"LayerName" =\> "%%14610",  
"SourceAddress" =\> "224.0.0.0",  
"Application" =\> "\device\harddiskvolume2\windows\system32\svchost.exe",  
"SourcePort" =\> "5355",  
"LayerRTID" =\> "44",  
"DestPort" =\> "61014",  
"RemoteMachineID" =\> "S-1-0-0",  
"Direction" =\> "%%14592",  
"Protocol" =\> "17",  
"RemoteUserID" =\> "S-1-0-0"  
},  
"beat" =\> {  
"name" =\> "web",  
"hostname" =\> "web",  
"version" =\> "5.4.0"  
},  
"record\_number" =\> "709132556",  
"version" =\> 1,  
"process\_id" =\> 4,  
"opcode" =\> "Info",  
"provider\_guid" =\> "{54849625-5478-4994-A00A-3E3B0328C30D}",  
"source\_name" =\> "Microsoft-Windows-Security-Auditing",  
"computer\_name" =\> "web",  
"event\_id" =\> 5156,  
"thread\_id" =\> 2908,  
"level" =\> "Information",  
"keywords" =\> [  
[0] "Audit Success"  
],  
"host" =\> "web",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
]  
}

I need to remove "beat" array and it should not appear in the log

"beat" =\> {  
"name" =\> "web",  
"hostname" =\> "web",  
"version" =\> "5.4.0"  
},

from log under filter mutate function. Following syntax doesn't work.

remove\_field =\> ["[beat]" ]  
remove\_field =\> ["[beat][name]" ]  
remove\_field =\> ["[beat][hostname]" ]  
remove\_field =\> ["[beat][version]" ]

and also need to remove content of a filed, in below under tags there is "beats\_input\_codec\_plain\_applied" and I need to remove that content, not the filed.

"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
]

So once it removed tags filed should blank.

Anyone who made changes under this scenario ?

---

<div class="post-metadata">

**Author:** ![xanadsonf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xanadsonf/32/18451_2.png) [@xanadsonf](https://discuss.elastic.co/u/xanadsonf)\
**Post date:** [May 24, 2017, 8:20am UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/2 "2017-05-24T08:20:46Z")

</div>

> [@tharu85](#):
>
> remove\_field =\> ["[beat]" ]

Concerning the first problem, you just need to remove beat field  
mutate {  
remove\_field =\> "beat"  
}

> [@tharu85](#):
>
> "tags" =\> [  
> [0] "beats\_input\_codec\_plain\_applied"  
> ]

You can either remove it with:  
filter {  
if "beats\_input\_codec\_plain\_applied" in [tags] {  
mutate {  
remove\_tag =\> ["beats\_input\_codec\_plain\_applied"]  
}  
}  
}

Or use  
`tag_on_failure => []`  
in your grok filter

---

<div class="post-metadata">

**Author:** ![tharu85](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@tharu85](https://discuss.elastic.co/u/tharu85)\
**Post date:** [May 24, 2017, 9:19am UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/3 "2017-05-24T09:19:13Z")

</div>

mutate {  
remove\_field =\> "beat"  
}

if "beats\_input\_codec\_plain\_applied" in [tags] {  
mutate {  
remove\_tag =\> ["beats\_input\_codec\_plain\_applied"]  
}  
}  
}

doesn't work.

---

<div class="post-metadata">

**Author:** ![xanadsonf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xanadsonf/32/18451_2.png) [@xanadsonf](https://discuss.elastic.co/u/xanadsonf)\
**Post date:** [May 24, 2017, 11:59am UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/4 "2017-05-24T11:59:29Z")

</div>

What do you mean by "doesn't" work ?

There is an error thrown? The first one does not work as expected? The second one? Both?

---

<div class="post-metadata">

**Author:** ![tharu85](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@tharu85](https://discuss.elastic.co/u/tharu85)\
**Post date:** [May 24, 2017, 12:30pm UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/5 "2017-05-24T12:30:05Z")

</div>

Both syntax that you are mentioned in previous post are not working. I have tested both syntax.

---

<div class="post-metadata">

**Author:** ![Toony](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/toony/32/18458_2.png) [@Toony](https://discuss.elastic.co/u/Toony)\
**Post date:** [May 24, 2017, 1:19pm UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/6 "2017-05-24T13:19:43Z")

</div>

Essaye ceci / Try this:

> remove\_field =\> ["beat"]

Ca devrait fonctionner mieux / It should work better

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 1:19pm UTC](https://discuss.elastic.co/t/remove-fields-on-windows-event-log/86891/7 "2017-06-21T13:19:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
