# Winlogbeat beta 5 - not dropping fields

**URL:** <https://discuss.elastic.co/t/winlogbeat-beta-5-not-dropping-fields/62096>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 3, 2016, 5:44pm UTC](https://discuss.elastic.co/t/winlogbeat-beta-5-not-dropping-fields/62096 "2016-10-03T17:44:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [October 3, 2016, 5:44pm UTC](https://discuss.elastic.co/t/winlogbeat-beta-5-not-dropping-fields/62096/1 "2016-10-03T17:44:42Z")

</div>

We are trying to anonymize some data by dropping some identifying data using the drop\_fields feature of winlogbeat 5. As I write this post, i think i am understanding the problem - does anyone have a suggestion? We wanted to drop the SubjectUserName and TargetUserName but i gather this is not parsed by the beat as it is packaged in a single field

we could drop the field on the server but would rather not see this data on our server.

Thoughts for how to remove fields within event\_data? We can not index it on the server side, but looking for a client-side solution.

processors:

- drop\_fields:  
fields: [computer\_name,host,beat.hostname,user.domain,[user.name](http://user.name), **event\_data.TargetDomainName,event\_data.TargetUserName,event\_data.SubjectDomainName,event\_data.SubjectUserName** ]

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 3, 2016, 6:16pm UTC](https://discuss.elastic.co/t/winlogbeat-beta-5-not-dropping-fields/62096/2 "2016-10-03T18:16:01Z")

</div>

I believe the source of the problem is that the `drop_fields` processor [quits](https://github.com/elastic/beats/blob/master/libbeat/processors/actions/drop_fields.go#L47-L49) when it hits any field that does not exist. Since "host" isn't a valid field (unless that's a custom field you've added) the processor always will stop there. I consider this a bug in the processor that it doesn't continue on error. Can you please open a new [elastic/beats](https://github.com/elastic/beats/issues/new) issue for this problem.

You might also want to format the config to be more readable (but that's a matter of preference).

```auto
processors:
- drop_fields:
    fields:
      - computer_name
      - beat.hostname
      - user.domain
      - user.name
      - event_data.TargetDomainName
      - event_data.TargetUserName
      - event_data.SubjectDomainName
      - event_data.SubjectUserName

```

You can workaround the issue by separating each field into it's own processor. Even if one processor fails due to the field not existing, it should continue to execute the remaining processors.

```auto
processors:
- drop_fields.fields: [computer_name]
- drop_fields.fields: [beat.hostname]
- drop_fields: 
    fields: 
      - user.domain 
- drop_fields: 
    fields: 
      - user.name 
- drop_fields: 
    fields: 
      - event_data.TargetDomainName 
- drop_fields: 
    fields: 
      - event_data.TargetUserName 
- drop_fields: 
    fields: 
      - event_data.SubjectDomainName 
- drop_fields: 
    fields: 
      - event_data.SubjectUserName

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2016, 6:16pm UTC](https://discuss.elastic.co/t/winlogbeat-beta-5-not-dropping-fields/62096/3 "2016-10-24T18:16:10Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
