# Aws ingest pipeline error in processor rename "message" to "event.original"

**URL:** <https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472>\
**Category:** Kibana\
**Created:** [August 23, 2023, 12:02pm UTC](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472 "2023-08-23T12:02:52Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 24, 2023, 2:33pm UTC](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472/8 "2023-08-24T14:33:50Z")

</div>

> [@diogoeverson](#):
>
> In this case, specifically the field been added is not a issue to me.

But it is an issue for the ingest pipeline.

Filebeat modules uses ingest pipelines in Elasticsearch, so it is expected that the original message collected will be sent directly to Elasticsearch.

When you add Logstash between filebeat and elasticsearch the original message can change and this can break the ingest pipeline in multiple points.

For example, in the [cloudtrail ingest pipeline](https://github.com/elastic/beats/blob/main/x-pack/filebeat/module/aws/cloudtrail/ingest/pipeline.yml), you have this processor in the beginning:

```auto
  - rename:
      field: "message"
      target_field: "event.original"

```

If the message arriving to elasticsearch already has a field named `event.original`, the pipeline will fail here and further processors will not be executed.

Logstash 8+ per default will add an `event.original` field, so it will probably break a lot of ingest pipelines, so you need to remove it as mentioned on the previous answer.

One thing is, why are you using Logstash? You can't change the original message, so Logstash will just act as a proxy to Elasticsearch in this case, it would be better to just send it directly to Elasticsearch.

Also, if you are just starting to collect logs with Elastic Stack I would recommend that you look into using the Elastic Agent and Fleet.

Filebeat modules are not being kept up to date and will probably be deprecated in the future, for example the [cloudtrail ingest pipeline in the elastic agent](https://github.com/elastic/integrations/blob/main/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml) will not fail if the `event.original` field already exists.

---

_[View the full topic](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472)._
