# Filebeat ingest

**URL:** https://discuss.elastic.co/t/filebeat-ingest/298242
**Category:** Beats
**Tags:** docker, beats-module
**Created:** [February 25, 2022, 5:02am UTC](https://discuss.elastic.co/t/filebeat-ingest/298242 "2022-02-25T05:02:32Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Anwar](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@Anwar](https://discuss.elastic.co/u/Anwar)
#### Post date: [February 25, 2022, 5:02am UTC](https://discuss.elastic.co/t/filebeat-ingest/298242/1 "2022-02-25T05:02:32Z")

</div>

Hi Team,

I want to use the below ingest directly in the Filebeat.yml file.

> <https://github.com/elastic/beats/blob/6b116c5b837e1760b787fbe4d02ca9a6088d1beb/x-pack/filebeat/module/aws/cloudtrail/ingest/pipeline.yml>

I have made changes for few processor. need to know -\> how to use grok, Geoip, user-agent and scripts.  
Please help me on the same.

Because, am using Filebeat.yml with Cloudtrail module for pushing the Cloudtrail log event to the elk using docker.  
The logs in elk is not parsed as expected.  
Note: I want to push it to Elasticsearch via Logstash only.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 25, 2022, 7:03am UTC](https://discuss.elastic.co/t/filebeat-ingest/298242/2 "2022-03-25T07:03:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
