# Removing a single value from an array

**URL:** <https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016>\
**Category:** Logstash\
**Created:** [March 12, 2019, 5:40pm UTC](https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016 "2019-03-12T17:40:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tszyro](https://avatars.discourse-cdn.com/v4/letter/t/9fc29f/32.png) [@tszyro](https://discuss.elastic.co/u/tszyro)\
**Post date:** [March 12, 2019, 5:40pm UTC](https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016/1 "2019-03-12T17:40:36Z")

</div>

I can't figure out how to remove a single value from an array.

I am trying to build a pipeline where I clone an event do different operation on the copy and finally output an original event into one index and the clone into different index.  
In short my pipeline looks as below. I have an input, add `@metadata.type` to it, then clone this input and change the `@metadata.type` to different value.  
All looks nearly good but after I output both event in the clone my `@metadata.type` has both the originally added value and the new one.  
What do I miss?  
How to do it most efficiently? (I don't like current solution anyway)  
**PIPELINES:**

```
input { stdin { } }
filter {
    json { source => "message" }
    mutate { add_tag => ["raw"] }
        mutate {
            add_field => { "[@metadata][type]" => "raw_route" } 
    }  
    # ==== cloning part ====
    clone {
        # Note that the field type will be added to the event by cloning ("type": "modified")
        clones => ['modified']
    }
    if [type] == "modified" {
        mutate {
            remove_field => ["@metadata"]
            remove_field => ["type"]
            add_field => { "[@metadata][type]" => "modified_route" } 
        }
    }
    # ==== modify filter ====
    if [@metadata][type] == "modified_route" {
        mutate { add_field => { "event" => "metrics" } }
    }
}
output { stdout { codec => rubydebug { metadata => true } } }

```

**INPUT:**

```
{"event.type": "reception"}

```

**OUTPUT:**

```
{
    "@timestamp" => 2019-03-12T17:26:08.333Z,
     "@metadata" => {
        "type" => "raw_route"
    },
    "event.type" => "reception",
      "@version" => "1",
       "message" => "{\"event.type\": \"reception\"}",
          "tags" => [
        [0] "raw"
    ]
}
{
    "@timestamp" => 2019-03-12T17:26:08.333Z,
     "@metadata" => {
        "type" => [
            [0] "raw_route",
            [1] "modified_route"
        ]
    },
    "event.type" => "reception",
      "@version" => "1",
       "message" => "{\"event.type\": \"reception\"}",
          "tags" => [
        [0] "raw"
    ]
}

```

**EXPECTED OUTPUT:** (Change in `@metadata.type` in second event, and added `"event" => "metrics"` to second event)

```
{
    "@timestamp" => 2019-03-12T17:26:08.333Z,
     "@metadata" => {
        "type" => "raw_route"
    },
    "event.type" => "reception",
      "@version" => "1",
       "message" => "{\"event.type\": \"reception\"}",
          "tags" => [
        [0] "raw"
    ]
}
{
    "@timestamp" => 2019-03-12T17:26:08.333Z,
     "@metadata" => {
        "type" => "modified_route"
    },
    "event.type" => "reception",
      "@version" => "1",
       "message" => "{\"event.type\": \"reception\"}",
         "event" => "metrics",
          "tags" => [
        [0] "raw"
    ]
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 12, 2019, 6:08pm UTC](https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016/2 "2019-03-12T18:08:25Z")

</div>

> [@tszyro](#):
>
> mutate { remove\_field =\> ["@metadata"] remove\_field =\> ["type"] add\_field =\> { "[@metadata][type]" =\> "modified\_route" } }

add\_field is executed [before](https://github.com/elastic/logstash/blob/fcd52c1573b5ff451cb25fdd4553592c4af33298/logstash-core/lib/logstash/filters/base.rb#L181) remove\_field. You need to use multiple mutate filters to force order.

However, even that will not work because you [cannot remove](https://github.com/logstash-plugins/logstash-filter-mutate/issues/77) sub-fields of @metadata.

---

<div class="post-metadata">

**Author:** ![tszyro](https://avatars.discourse-cdn.com/v4/letter/t/9fc29f/32.png) [@tszyro](https://discuss.elastic.co/u/tszyro)\
**Post date:** [March 12, 2019, 7:07pm UTC](https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016/3 "2019-03-12T19:07:29Z")

</div>

Thanks @Badger, could you please advise some working solution?  
Is there a way to do it at all?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 12, 2019, 7:49pm UTC](https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016/4 "2019-03-12T19:49:14Z")

</div>

Replace the second mutate+add\_field with mutate+replace.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2019, 7:49pm UTC](https://discuss.elastic.co/t/removing-a-single-value-from-an-array/172016/5 "2019-04-09T19:49:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
