# Remove unnecessary exported fields

**URL:** <https://discuss.elastic.co/t/remove-unnecessary-exported-fields/345674>\
**Category:** Metrics\
**Tags:** elastic-stack-monitoring\
**Created:** [October 24, 2023, 9:35pm UTC](https://discuss.elastic.co/t/remove-unnecessary-exported-fields/345674 "2023-10-24T21:35:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [October 24, 2023, 9:35pm UTC](https://discuss.elastic.co/t/remove-unnecessary-exported-fields/345674/1 "2023-10-24T21:35:31Z")

</div>

Hello,  
Is there any way how to remove unnecessary exported fields before indexing?  
Using Elastic Agent integration, and along with it comes many exported fields. Tried Elastic Agent processor "drop\_fields", but all listed fields for dropping still apears in document. Another option would be to use ingestion pipeline, but at this point it would be more costly and processing in the Agent itself is more preffered.

Just a short example used in configuration file:

```auto
processors:
  - drop_fields:
      fields:
        - "cloud.provider"
        - "cloud.region"
        - "host.mac"
        - "host.os.family"
        - "host.os.kernel"
        - "host.os.name"
        - "host.os.codename"
     ignore missing: true

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 25, 2023, 1:11am UTC](https://discuss.elastic.co/t/remove-unnecessary-exported-fields/345674/2 "2023-10-25T01:11:42Z")

</div>

Hi @s.buksa

What version are you using?

If I recall, unfortunately most of those fields, the host, and agent fields are actually added **after** The agent processors are run.

I agree, not ideal. So I am fairly sure you're going to have to drop them in an ingest pipeline after they arrive at Elasticsearch.

I'm not sure if the fix of this is on our roadmap, but you certainly can open an issue if you'd like.

---

<div class="post-metadata">

**Author:** ![s.buksa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s.buksa/32/124525_2.png) [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Post date:** [October 25, 2023, 5:35am UTC](https://discuss.elastic.co/t/remove-unnecessary-exported-fields/345674/3 "2023-10-25T05:35:04Z")

</div>

Hi,  
Thank you for your reply. I'm using version 8.9.2.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2023, 3:41pm UTC](https://discuss.elastic.co/t/remove-unnecessary-exported-fields/345674/5 "2023-12-15T15:41:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
