# Unable to drop field from aws module

**URL:** <https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 9, 2020, 2:50pm UTC](https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845 "2020-05-09T14:50:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronin](https://avatars.discourse-cdn.com/v4/letter/r/ad7895/32.png) [@Ronin](https://discuss.elastic.co/u/Ronin)\
**Post date:** [May 9, 2020, 2:50pm UTC](https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845/1 "2020-05-09T14:50:30Z")

</div>

I have the following config:

```auto
filebeat.modules:
- module: aws
  cloudtrail:
    enabled: true
    var.queue_url: https://sqs.us-east-1.amazonaws.com/xxxxxxx/yyyyyyyyy
  cloudwatch:
    enabled: false
  ec2:
    enabled: false
  elb:
    enabled: false
  s3access:
    enabled: false
  vpcflow:
    enabled: false
processors:
- drop_fields:
    fields: ["agent.ephemeral_id", "agent.hostname", "agent.id", "agent.type", "agent.version", "event.original"]
    ignore_missing: true

```

All fields drop successfully, except `event.original`.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [May 10, 2020, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845/2 "2020-05-10T13:26:51Z")

</div>

Hi @Ronin,

Filebeat events processing happens in two places when using modules: first, local processors are executed, then the event is sent to Elasticsearch, where another pipeline is executed. For the case of cloudtrail the pipeline in Elasticsearch is the one creating the `event.original` field ([here](https://github.com/elastic/beats/blob/v7.6.2/x-pack/filebeat/module/aws/cloudtrail/ingest/pipeline.yml#L6)). There is no option at the moment to remove this field.

There are two things you could try:

- Use the [S3 input](https://www.elastic.co/guide/en/beats/filebeat/7.6/filebeat-input-s3.html) directly instead of the `cloudtrail` module. This way you would have total control on the processing of events, but you would also be missing everything included in this module.
- Modify the cloudtrail pipeline to remove the `event.original` field. Pipelines are installed by filebeat, and they are included in filebeat distributions, under `/usr/share/filebeat/module/`. You could modify it, and reinstall the pipeline with `filebeat setup --pipelines --module aws`. This has the problem that you will have to repeat the process every time you upgrade filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2020, 1:27pm UTC](https://discuss.elastic.co/t/unable-to-drop-field-from-aws-module/231845/3 "2020-06-07T13:27:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
