# Filebeat modules

**URL:** https://discuss.elastic.co/t/filebeat-modules/276862
**Category:** Elasticsearch
**Tags:** ingest-pipeline
**Created:** [June 24, 2021, 2:33am UTC](https://discuss.elastic.co/t/filebeat-modules/276862 "2021-06-24T02:33:26Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![leemase004](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@leemase004](https://discuss.elastic.co/u/leemase004)
#### Post date: [June 24, 2021, 2:33am UTC](https://discuss.elastic.co/t/filebeat-modules/276862/1 "2021-06-24T02:33:26Z")

</div>

We inherited a cluster and are trying to update the ingest pipeline (ES version 7.6)

Context: When we do GET ingest/pipeline there is a 15k line pipeline. It has all the processors from the filebeat modules they have uploaded: mysql,bro/zeek,suricata,aws,apache,azure etc. (they pretty much put in every module to provide for future expansion)

1. We are wondering how can we add/adjust one specific module? If there are 5 modules loaded into one specific pipeline: How can we "PUT ingest/Pipeline" and make sure it only goes to the Mysql section of the pipeline?

2. Is there a way to cat out all the pipelines that have been created? We run the GET ingest/pipeline and that returns the massive 15k pipeline but we are trying to see if there are other pipelines that have been created.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [June 24, 2021, 5:07am UTC](https://discuss.elastic.co/t/filebeat-modules/276862/2 "2021-06-24T05:07:32Z")

</div>

1. You can setup a single module, yes. I don't know how Filebeat handles that in terms of ingest pipelines and loading everything though, which is the distinction you are looking for. It'd be worth creating a topic in #beats to ask more about that.

2. Unfortunately only the way you have done it, you might be able to do some `jq` foo to filter things down though. Otherwise check out [Cat endpoint for ingest pipelines · Issue #31954 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/31954) and add a +1 reaction to the OP so can see what sort of demand there is for this.

> [@leemase004](#):
>
> ES version 7.6

I'd definitely recommend upgrading, 7.13 is latest and it's good to keep close to current if you can!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 22, 2021, 5:08am UTC](https://discuss.elastic.co/t/filebeat-modules/276862/3 "2021-07-22T05:08:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
