# Alternative to ingest-convert.sh for YML

**URL:** <https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597>\
**Category:** Logstash\
**Created:** [November 8, 2021, 8:15am UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597 "2021-11-08T08:15:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![IsaacKr](https://avatars.discourse-cdn.com/v4/letter/i/c89c15/32.png) [@IsaacKr](https://discuss.elastic.co/u/IsaacKr)\
**Post date:** [November 8, 2021, 8:15am UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597/1 "2021-11-08T08:15:45Z")

</div>

We are using Logstash to ship logs to a cloud based SIEM. We'd like to utilize Filebeat to assist in the parsing, however it seems that Filebeat only provides the ingest pipelines for Elasticsearch. The ingest-convert.sh is supposed to convert ingest files to Logstash configs, but it expects JSON, while all the Filebeat modules utilize YAML. Is there an alternative to this converter or a workaround?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 8, 2021, 1:16pm UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597/2 "2021-11-08T13:16:35Z")

</div>

I would say that the workaround would be load those ingest pipelines in a Elasticsearch server, get the json of the ingest pipeline and use the converter.

---

<div class="post-metadata">

**Author:** ![IsaacKr](https://avatars.discourse-cdn.com/v4/letter/i/c89c15/32.png) [@IsaacKr](https://discuss.elastic.co/u/IsaacKr)\
**Post date:** [November 8, 2021, 7:03pm UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597/3 "2021-11-08T19:03:22Z")

</div>

Where is the JSON file generated? Do I need to receive logs in order to generate it, or is it enough to run a module test?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 8, 2021, 7:30pm UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597/4 "2021-11-08T19:30:50Z")

</div>

You need to configure filebeat to connect to an Elasticsearch cluster first, so it will be able to install the ingest pipelines.

Then you can get the json of the pipeline using the [API](https://www.elastic.co/guide/en/elasticsearch/reference/master/get-pipeline-api.html#get-pipeline-api).

Use `GET /_ingest/pipeline` to list the pipelines and `GET /_ingest/pipeline/<pipeline-name>` to get the specific pipeline.

---

<div class="post-metadata">

**Author:** ![IsaacKr](https://avatars.discourse-cdn.com/v4/letter/i/c89c15/32.png) [@IsaacKr](https://discuss.elastic.co/u/IsaacKr)\
**Post date:** [November 9, 2021, 11:42am UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597/5 "2021-11-09T11:42:27Z")

</div>

Thanks. Is there documentation where I can find how to do this?  
I've set Elasticsearch as the output in /etc/filebeat/filebeat.yml, configured the relevant filebeat modules, loaded the pipelines with `filebeat setup --pipelines --modules` and restarted the filebeat service. But the API is returning `{ }` for `/_ingest/pipeline`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2021, 11:42am UTC](https://discuss.elastic.co/t/alternative-to-ingest-convert-sh-for-yml/288597/6 "2021-12-07T11:42:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
