# Customize ingest pipelines in Fleet / Elastic Agent

**URL:** <https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236>\
**Category:** Beats\
**Tags:** fleet, filebeat\
**Created:** [January 5, 2021, 4:31pm UTC](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236 "2021-01-05T16:31:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 5, 2021, 4:31pm UTC](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236/1 "2021-01-05T16:31:32Z")

</div>

Hello,

I was fiddling around with Elastic Agent and Fleet to integrate multiple log sources in the same agent, and I am getting "Provided Grok expressions do not match field value" error with Fortinet integration.

Using Filebeat I was able to "bypass" this error modifying Grok pattern to match my logs' format, but when I try to adapt Elastic Agent ingest pipelines the same way, it does not work. I tried modifying them manually from Kibana and Elastic Agent's data folder, but none of them worked.

So my question is, is there a way to modify Grok patterns used in Fleet integrations or should I stick to Filebeat only?

Thank you in advance

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 6, 2021, 10:11am UTC](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236/2 "2021-01-06T10:11:08Z")

</div>

Hi @icious Welcome to the forum.

I have opened a PR here some time ago with some docs related to this: [https://github.com/elastic/beats/pull/23247](https://github.com/elastic/beats/pull/23247) You can modify the ingest pipeline directly in Elasticsearch and it should work. But be aware that the next update of the package will overwrite it and is not what you want. What you can do as an alternative is describe in the PR.

The modifications you are making, are they specific to your use case or more generic? If more generic, perhaps these could be contributed here to the fortinet package/integration: [https://github.com/elastic/integrations/tree/master/packages/fortinet](https://github.com/elastic/integrations/tree/master/packages/fortinet) Like this they would be available to everyone in the next version.

---

<div class="post-metadata">

**Author:** ![icious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icious/32/77965_2.png) [@icious](https://discuss.elastic.co/u/icious)\
**Post date:** [January 8, 2021, 12:35pm UTC](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236/3 "2021-01-08T12:35:06Z")

</div>

Hi @ruflin, modifying the ingest pipeline directly from Elasticsearch has worked fine. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2021, 12:35pm UTC](https://discuss.elastic.co/t/customize-ingest-pipelines-in-fleet-elastic-agent/260236/4 "2021-02-05T12:35:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
