# Remove Parent fields in logstash filter

**URL:** <https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646>\
**Category:** Logstash\
**Created:** [January 9, 2024, 11:42am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646 "2024-01-09T11:42:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Priyanka\_chauhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyanka_chauhan/32/86146_2.png) [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Post date:** [January 9, 2024, 11:42am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/1 "2024-01-09T11:42:08Z")

</div>

I have large log json message which I have to parse to visualize at kibana.  
I have used json filter first to parse message but there are generated lots of parent and dynamic fields. Due to dynamic fields in each log message number of fields are increasing and kibana is slow. I want to remove to get unique fields for each log. how to resolve this issue. For the below example like I want to remove parent fields like nodes.processes.dynamicvalue  
some part of message after applying json filter  
example:  
nodes.processes.2A2807E813FE36C5.fullPid.startTime.millisecondsSinceEpoch  
1704797811445  
nodes.processes.2A2807E813FE36C5.group.key.value  
C55706E813FE36C5  
nodes.processes.2A2807E813FE36C5.integrityLevel  
LOW  
nodes.processes.2A2807E813FE36C5.name  
Microsoft Edge  
nodes.processes.2A2807E813FE36C5.node.key.value  
2A2807E813FE36C5  
nodes.processes.2A2807E813FE36C5.parent.key.value  
5A2607E813FE36C5  
nodes.processes.2A2807E813FE36C5.sessionId  
1  
nodes.processes.2A2807E813FE36C5.subsystem  
SYS\_WIN32  
nodes.processes.2A2807E813FE36C5.user.name  
SANJAY-AIO\sgupta  
nodes.processes.2A2807E813FE36C5.user.sid  
S-1-5-21-3758888377-4075476628-3217939268-1002  
nodes.processes.3D0B07E813FE36C5.activeContent.signed  
E\_FALSE  
nodes.processes.3D0B07E813FE36C5.activeContent.type  
AC\_FILE  
nodes.processes.3D0B07E813FE36C5.commandLine  
"C:\Program Files\Mozilla Firefox\firefox.exe"  
nodes.processes.3D0B07E813FE36C5.completenessHintsBitmask  
263168

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 9, 2024, 12:28pm UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/2 "2024-01-09T12:28:21Z")

</div>

You want to remove the `node.processes` top level field?

If so, the following filter may work.

```auto
filter {
    mutate {
        remove_field => ["[nodes][processes]"]
    }
}

```

---

<div class="post-metadata">

**Author:** ![Priyanka\_chauhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyanka_chauhan/32/86146_2.png) [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Post date:** [January 9, 2024, 12:49pm UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/3 "2024-01-09T12:49:43Z")

</div>

I also want to remove parent3 fileld which is dynamic

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 9, 2024, 12:52pm UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/4 "2024-01-09T12:52:40Z")

</div>

> [@Priyanka\_chauhan](#):
>
> I also want to remove parent3 fileld which is dynamic

Then you will need to use a `ruby` filter and write some code to do that, I do not have much experience in ruby but there are a couple of questions already answered in the forum about this.

Also, after you remove all the dynamic fields after `nodes.processes`, will it have anything left? If not then it is easier to just remove `nodes.processes`.

---

<div class="post-metadata">

**Author:** ![Priyanka\_chauhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyanka_chauhan/32/86146_2.png) [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Post date:** [January 10, 2024, 6:42am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/5 "2024-01-10T06:42:31Z")

</div>

Yes there are more fields which left after deleting nodes.processes.dynamicvalue.  
I have used the code following for the above : this is my filter file. here json filter is working but parent fields are not deleting. I have already tested online regex pattern tester tool for check regex pattern, it is correct. but in logstash this code is not working  
filter {  
json {  
source =\> "message"  
}

ruby {  
code =\> "  
event.to\_hash.keys.each do |key|  
if key.start\_with?('nodes.files.')  
new\_key = key.gsub(/^nodes.files.([^.]+)./, '')  
event.set(new\_key, event.get(key))  
event.remove(key)  
end  
end  
"  
}  
}

---

<div class="post-metadata">

**Author:** ![Priyanka\_chauhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyanka_chauhan/32/86146_2.png) [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Post date:** [January 10, 2024, 6:45am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/6 "2024-01-10T06:45:26Z")

</div>

> [@Priyanka\_chauhan](#):
>
> I have used the code following for the above : this is my filter file. here json filter is working but parent fields are not deleting. I have already tested online regex pattern tester tool for check regex pattern, it is correct. but in logstash this code is not working  
> filter {  
> json {  
> source =\> "message"  
> }
> 
> ruby {  
> code =\> "  
> event.to\_hash.keys.each do |key|  
> if key.start\_with?('nodes.processes.')  
> new\_key = key.gsub(/^nodes.processes.([^.]+)./, '')  
> event.set(new\_key, event.get(key))  
> event.remove(key)  
> end  
> end  
> "  
> }  
> }

How to fix it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2024, 6:45am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646/7 "2024-02-07T06:45:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
