# Removing subfield in the elasticsearch output display

**URL:** <https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494>\
**Category:** Elasticsearch\
**Created:** [June 30, 2021, 7:48pm UTC](https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494 "2021-06-30T19:48:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gisellecarballo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gisellecarballo/32/112755_2.png) [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Post date:** [June 30, 2021, 7:48pm UTC](https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494/1 "2021-06-30T19:48:36Z")

</div>

Hi,  
Anyone knows how to remove the subfield alone in the elasticsearch display output.  
In the output there are fields "host: 192.x.x.x" "host.keyword: 192.x.x.x" I want to remove the host.keyword field.

Current filter:  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
kv {  
source =\> "message"  
field\_split =\> " "  
}  
mutate {  
remove\_field =\> ["@version", "facility", "facility\_label"]  
remove\_field =\> ["host.keyword", "logsource.keyword", "tags", "priority", "severity"]  
}  
}

Web Dispaly:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7f3b2053f70ffcd2c16eadf9ee958ca16db4346.png)

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [June 30, 2021, 8:19pm UTC](https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494/2 "2021-06-30T20:19:32Z")

</div>

The "host.keyword" field is not present when Logstash is processing the document, is created when the document is indexed, you have to change in the mapping the type of the field, my understanding is that the field is mapped something like this:

```auto
	"host": {
		"ignore_above": 1024,
		"type": "keyword",
		"fields": {
			"text": {
				"norms": false,
				"type": "text"
			}
		}
	},

```

Given the type of value, maybe is better:

```auto
        "host": {
          "ignore_above": 1024,
          "type": "keyword"
        },

```

---

<div class="post-metadata">

**Author:** ![gisellecarballo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gisellecarballo/32/112755_2.png) [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Post date:** [June 30, 2021, 9:07pm UTC](https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494/3 "2021-06-30T21:07:59Z")

</div>

Hi @Iker ,

Thanks for the reply. Im just new to elk. do you know where I can check the mapping ?  
TIA!

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [July 1, 2021, 1:25am UTC](https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494/4 "2021-07-01T01:25:13Z")

</div>

Check what index is using, in Kibana UI you could look at the templates in the index management section.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2021, 1:25am UTC](https://discuss.elastic.co/t/removing-subfield-in-the-elasticsearch-output-display/277494/5 "2021-07-29T01:25:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
