# Coupling Filebeat prospector with Logstash pipeline

**URL:** <https://discuss.elastic.co/t/coupling-filebeat-prospector-with-logstash-pipeline/108349>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 20, 2017, 9:19am UTC](https://discuss.elastic.co/t/coupling-filebeat-prospector-with-logstash-pipeline/108349 "2017-11-20T09:19:14Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 21, 2017, 12:33am UTC](https://discuss.elastic.co/t/coupling-filebeat-prospector-with-logstash-pipeline/108349/2 "2017-11-21T00:33:01Z")

</div>

This would require some kind of filtering + forward to another pipeline in Logstash. I don't think this is possible as is with Logstash. e.g. see: [Logstash 6 - Multiple Pipelines for One Input](https://discuss.elastic.co/t/logstash-6-multiple-pipelines-for-one-input/107929)

In filebeat in the prospector you can either use the `fields` setting to pass additional fields for filtering or use the `pipeline` setting in filebeat. The later is somewhat private and used by filebeat to set the ingest node pipeline name for the Elasticsearch output. The `pipeline` setting of each prospector is available in the event via `[@metadata][pipeline]`. You can still have separate processing 'pipelines/filters' so to say, by guarding those on the `pipeline` contents. Each prospector specific processing would be wrapped into this:

```auto
if [@metadata][pipeline] {
  mutate {
    remove_field => ["[@metadata][pipeline]"]
  }

  # custom per prospector filters
}

```

If you really filter on `[@metadata][pipeline]`, make sure to remove it as well. With 6.0 we ask users to set the ingest node pipeline via `[@metadata][pipeline]`. Or rather use a custom field.

---

_[View the full topic](https://discuss.elastic.co/t/coupling-filebeat-prospector-with-logstash-pipeline/108349)._
