Removing fields from logstash

You are on the right way:

You can operate on the fields you get afterwards..

PS: Logstash is a dedicated product for logs ingestion and way easier to operate than the elasticsearch ingestion pipelines. So I discourage the suggestion from Samuele_Lolli.