# \[SOLVED\]How to remove agent.\* and ecs.version?

**URL:** <https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 31, 2019, 2:29am UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643 "2019-05-31T02:29:35Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Duked](https://avatars.discourse-cdn.com/v4/letter/d/a4c791/32.png) [@Duked](https://discuss.elastic.co/u/Duked)\
**Post date:** [May 31, 2019, 2:29am UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/1 "2019-05-31T02:29:35Z")

</div>

Hi,

I've tried disabling all the processor metadata and somehow narrowed it down but I still can't get rid of agent.ephemeral\_id, agent.hostname, agent.id, agent.type, agent.version and ecs.version and log.offset.

Is there a way to disable it or I have to manually specify them in the logstash config to make sure they don't get ingested/indexed ?

thanks !

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [May 31, 2019, 7:19am UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/2 "2019-05-31T07:19:54Z")

</div>

You can drop them from filebeat, logstash or configure the mapping/index template to change how they are treated: index or not, doc\_values or not, etc.

I'd say you are looking for how to drop fields, from filebeat, you would do it with this:  
[https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/drop-fields.html)

---

<div class="post-metadata">

**Author:** ![Duked](https://avatars.discourse-cdn.com/v4/letter/d/a4c791/32.png) [@Duked](https://discuss.elastic.co/u/Duked)\
**Post date:** [May 31, 2019, 12:54pm UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/3 "2019-05-31T12:54:15Z")

</div>

Thanks @martinr_ubi. I thought there would be an option in filebeat directly to drop all meta data 😕

I'll do it the way you suggested unless someone knows a better way 😉

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [May 31, 2019, 2:06pm UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/4 "2019-05-31T14:06:27Z")

</div>

If this feature exists, it's a hidden undocumented feature so I think it's safe to assume it doesn't exists.  
Make sense, those fields are part of the basic functionality of the Beats. You'll break a bunch of stuff by dropping them. But I have to assume you have a custom setup already and are not using any of the features that use those fields.

---

<div class="post-metadata">

**Author:** ![Duked](https://avatars.discourse-cdn.com/v4/letter/d/a4c791/32.png) [@Duked](https://discuss.elastic.co/u/Duked)\
**Post date:** [June 4, 2019, 4:10pm UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/5 "2019-06-04T16:10:51Z")

</div>

Ok I tried dropping it from filebeat but it doesn't seem to work anyone has an idea as to way this config fails:

processors:  
- drop\_fields:  
when:  
equals  
fields: ["agent.ephemeral\_id", "agent.hostname", "agent.id", "agent.type", "agent.version", "ecs.version", "input.type", "log.offset"]

from filebeat.yml

---

<div class="post-metadata">

**Author:** ![Duked](https://avatars.discourse-cdn.com/v4/letter/d/a4c791/32.png) [@Duked](https://discuss.elastic.co/u/Duked)\
**Post date:** [June 4, 2019, 4:42pm UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/7 "2019-06-04T16:42:12Z")

</div>

Ok in case this can help some people here it worked it was just some indent issues in the filebeat.yml file.

It works with the following processor definition:

```auto
processors:
  - drop_fields:
      fields: ["agent.ephemeral_id", "agent.hostname", "agent.id", "agent.type", "agent.version", "ecs.version", "input.type", "log.offset", "version"]

```

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [June 4, 2019, 10:36pm UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/8 "2019-06-04T22:36:07Z")

</div>

All of it looks like crap to any reading the forums 🙂 hehe

Always enclose the config you post in proper formatting:  
The \</\> button in the forum post editor or triple back ticks. ```  
I prefer the backticks, easier I think.

Like this:

```auto
processors:
- <processor_name>:
    when:
      <condition>
    <parameters>

- <processor_name>:
    when:
      <condition>
    <parameters>

```

There is a post preview feature to check what it looks like and it is the only way to share config snippets or files correctly embedded. Or a github gist, etc.

---

<div class="post-metadata">

**Author:** ![Duked](https://avatars.discourse-cdn.com/v4/letter/d/a4c791/32.png) [@Duked](https://discuss.elastic.co/u/Duked)\
**Post date:** [June 5, 2019, 12:51am UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/9 "2019-06-05T00:51:05Z")

</div>

thanks I've edited the previous post with proper formatting in case someone faces the same issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2019, 12:51am UTC](https://discuss.elastic.co/t/solved-how-to-remove-agent-and-ecs-version/183643/10 "2019-07-03T00:51:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
