# Remove message and replace timestamp fields

**URL:** <https://discuss.elastic.co/t/remove-message-and-replace-timestamp-fields/226025>\
**Category:** Logstash\
**Created:** [April 1, 2020, 10:43am UTC](https://discuss.elastic.co/t/remove-message-and-replace-timestamp-fields/226025 "2020-04-01T10:43:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![manikandanb87](https://avatars.discourse-cdn.com/v4/letter/m/278dde/32.png) [@manikandanb87](https://discuss.elastic.co/u/manikandanb87)\
**Post date:** [April 1, 2020, 10:43am UTC](https://discuss.elastic.co/t/remove-message-and-replace-timestamp-fields/226025/1 "2020-04-01T10:43:33Z")

</div>

Hi Experts,  
I am using log stash to read my logs and I notice that the field "message" is there by default and has the complete data in it. So, I would like to remove it from my feed.

Also, I want to replace "@timestamp" with "app\_timestamp". Kindly help.

```auto
{
            "message" => "JVM.128077 (437) [2020-03-31T11:56:24.569 Usercheck] c9qnpn/QLB2UyA 1610670968891559937 - (3) Sign on Code failed for user USERA@xxx.xxx.xxx.xx",
              "oprid" => "-",
               "host" => "nonpselastic",
                "pid" => "128077",
    "service_request" => "437",
            "process" => "JVM",
        "log_message" => "Sign on Code failed for user USERA@xxx.xxx.xxx.xx",
         "@timestamp" => 2020-04-01T10:31:17.279Z,
         "tuxservice" => "Usercheck",
      "TOPInstanceID" => "1610670968891559937",
           "@version" => "1",
      "app_timestamp" => "2020-03-31T11:56:24.569",
               "SRID" => "c9qnpn/QLB2UyA",
          "log_level" => "3",
               "path" => "/searchtech/logstash-7.6.1/bin/failelogin.log"
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 1, 2020, 3:10pm UTC](https://discuss.elastic.co/t/remove-message-and-replace-timestamp-fields/226025/2 "2020-04-01T15:10:38Z")

</div>

You can remove a field using mutate

```
mutate { remove_field => ["message"] }

```

Use a date filter to parse app\_timestamp and overwrite @timestamp.

---

<div class="post-metadata">

**Author:** ![manikandanb87](https://avatars.discourse-cdn.com/v4/letter/m/278dde/32.png) [@manikandanb87](https://discuss.elastic.co/u/manikandanb87)\
**Post date:** [April 1, 2020, 3:49pm UTC](https://discuss.elastic.co/t/remove-message-and-replace-timestamp-fields/226025/3 "2020-04-01T15:49:56Z")

</div>

Thank you!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 3:50pm UTC](https://discuss.elastic.co/t/remove-message-and-replace-timestamp-fields/226025/4 "2020-04-29T15:50:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
