# ./filebeat generate fields with pipeline.yml

**URL:** <https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [July 3, 2020, 11:42am UTC](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790 "2020-07-03T11:42:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bernhard.fluehmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernhard.fluehmann/32/71755_2.png) [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Post date:** [July 3, 2020, 11:42am UTC](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790/1 "2020-07-03T11:42:37Z")

</div>

I am developing a new filebeat module for sophos firewall logs. Now I got stuck on  
the ./filebeat generate fields command. It returns with the following error:

> cannot read pipeline: open module/sophos/secureweb/ingest/pipeline.json: no such file or directory

This makes sense since my pipeline is called pipeline.yml. It is configured like this in the manifest file of the fileset. I have though already to convert the file back to json but since almost all pipelines of the existing modules are in yml I wonder what I am doing wrong.

Regards  
Bernhard

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [July 6, 2020, 3:23pm UTC](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790/2 "2020-07-06T15:23:08Z")

</div>

The generator you are trying to use expects JSON piplines not YAML. Unfortunately, this generator is not up to date and does not support YAML. Could you please open an issue on GH?

---

<div class="post-metadata">

**Author:** ![bernhard.fluehmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernhard.fluehmann/32/71755_2.png) [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Post date:** [July 7, 2020, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790/4 "2020-07-07T14:14:43Z")

</div>

Hi @kvch,  
Thank you for your answer. I will open a GH issue as you propose.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2020, 4:14pm UTC](https://discuss.elastic.co/t/filebeat-generate-fields-with-pipeline-yml/239790/5 "2020-08-04T16:14:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
