# \[Solved\]Mutate not working

**URL:** <https://discuss.elastic.co/t/solved-mutate-not-working/125948>\
**Category:** Logstash\
**Created:** [March 28, 2018, 1:57pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948 "2018-03-28T13:57:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wakame](https://avatars.discourse-cdn.com/v4/letter/w/d9b06d/32.png) [@wakame](https://discuss.elastic.co/u/wakame)\
**Post date:** [March 28, 2018, 1:57pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948/1 "2018-03-28T13:57:41Z")

</div>

I upgraded logstash from 2.3.4 to 5.6.7, after the upgrade, mutate failed to remove any of the field. What do I need to check to make sure I have the right plugin?

LS 5.6.7  
ES 2.4.1

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 28, 2018, 2:02pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948/2 "2018-03-28T14:02:54Z")

</div>

I'm sure you have the right plugin. Perhaps you were relying on undocumented behavior that happened to change in recent Logstash releases. If you show us your configuration and an example input event we can help out.

---

<div class="post-metadata">

**Author:** ![wakame](https://avatars.discourse-cdn.com/v4/letter/w/d9b06d/32.png) [@wakame](https://discuss.elastic.co/u/wakame)\
**Post date:** [March 28, 2018, 2:10pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948/3 "2018-03-28T14:10:26Z")

</div>

input {  
kafka {group\_id=\>"xxxxxx" topics =\>"xxxxx" type=\>"route" bootstrap\_servers=\>"IP:9092" consumer\_threads=\>3} }  
filter {  
if [type] == "route" { mutate { remove\_field =\> ["api\_id"] } json{source=\>"message" }} }

{  
"\_index": "xxxxxx",  
"\_type": "route",  
"\_id": "xxxxxxxxx",  
"\_score": null,  
"\_source": {  
"api\_id": "xxxxxxxx",  
}

even just removing one field, I couldn't get it to work.

---

<div class="post-metadata">

**Author:** ![wakame](https://avatars.discourse-cdn.com/v4/letter/w/d9b06d/32.png) [@wakame](https://discuss.elastic.co/u/wakame)\
**Post date:** [March 29, 2018, 3:22pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948/4 "2018-03-29T15:22:34Z")

</div>

I had to move

json{source=\>"message" }

to the front of my filter and it started working.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 30, 2018, 7:54pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948/5 "2018-03-30T19:54:29Z")

</div>

The document clearly doesn't have a `type` field so the `if [type] == "route"` conditional is false.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2018, 7:55pm UTC](https://discuss.elastic.co/t/solved-mutate-not-working/125948/6 "2018-04-27T19:55:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
