# Too many field in metricbeat

**URL:** https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572
**Category:** Beats
**Tags:** metricbeat
**Created:** [July 24, 2020, 10:07pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572 "2020-07-24T22:07:45Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [July 24, 2020, 10:07pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/1 "2020-07-24T22:07:45Z")

</div>

When I start the metricbeat it loads about 3000 field.

I know it is loading default template. even when I have only one module.d/system.yml file.

how do I only load system template?

---

<div class="post-metadata">

### Author: ![tactics](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@tactics](https://discuss.elastic.co/u/tactics)
#### Post date: [July 26, 2020, 2:40pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/2 "2020-07-26T14:40:34Z")

</div>

I have just posted about this too:  
[https://discuss.elastic.co/t/filebeat-index-template-from-modules/242660](https://discuss.elastic.co/t/filebeat-index-template-from-modules/242660)

Not sure if this creates an issue or not but it would be really nice to know for sure. Got to be a way of only including the used fields from any given module in the index template.

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [July 26, 2020, 5:37pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/3 "2020-07-26T17:37:34Z")

</div>

thanks  
Lets see if someone has gone through this and knows how to do this.  
I am still testing to figure out.

I have gone through kibana UI and modify default metricbeat template to trim down #field to 500 but still don't know how to do this cleanly

---

<div class="post-metadata">

### Author: ![tactics](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@tactics](https://discuss.elastic.co/u/tactics)
#### Post date: [July 27, 2020, 2:11pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/4 "2020-07-27T14:11:42Z")

</div>

@elasticforme - I have tried editing the fields.yml to remove the modules that aren't needed, this has reduced the number of fields in my index template. Still checking to see if there are any issues with this but this might work for you as well.

> [@Filebeat Index Template from Modules](https://discuss.elastic.co/t/filebeat-index-template-from-modules/242660):
>
> Hi, Not sure if I am overcomplicating things and bothering unnecessarily... I have finally got apache logs importing nicely using Filebeat and the Apache module. I am simply using the fields.yml and therefore the index template is massive... Is there any way to only include the fields that are used in the module or maybe use the Index to generate fields and mappings that are being used? Maybe I don't actually need to worry about this as the field definitions and mappings don't take up space…

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [July 27, 2020, 6:03pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/5 "2020-07-27T18:03:32Z")

</div>

Anyone's input idea welcome

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [July 28, 2020, 1:17pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/6 "2020-07-28T13:17:34Z")

</div>

giving last bump. I can't believe no one has face this issue

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [August 5, 2020, 4:29pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/7 "2020-08-05T16:29:12Z")

</div>

does anyone has done anything to fix this.

I just started filebeat to monitor only logstash but it loaded everything from template.

how do I only load what I need. where is this default template?

---

<div class="post-metadata">

### Author: ![di.lu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/di.lu/32/94248_2.png) [@di.lu](https://discuss.elastic.co/u/di.lu)
#### Post date: [August 11, 2020, 6:38am UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/8 "2020-08-11T06:38:02Z")

</div>

I edited the fields.yml myself to only look at certain fields I need. With regards to the default template, it can be exported by "metricbeat export template" command, according to this doc: [https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-template.html](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-template.html)

---

<div class="post-metadata">

### Author: ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)
#### Post date: [August 11, 2020, 12:55pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/9 "2020-08-11T12:55:03Z")

</div>

Thank you I did update fields.yml file finally. it was 30,000+ line trim down to 2000 line to get me only systems, elasticsearch and kibana matric.

hopefully elastic can develop something which loads only module that I user need. I have not found proper command for it. this is long and ugly process.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 8, 2020, 2:55pm UTC](https://discuss.elastic.co/t/too-many-field-in-metricbeat/242572/10 "2020-09-08T14:55:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
