# Filebeat Modules

**URL:** https://discuss.elastic.co/t/filebeat-modules/276949
**Category:** Beats
**Tags:** filebeat
**Created:** [June 24, 2021, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-modules/276949 "2021-06-24T14:56:24Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![leemase004](https://avatars.discourse-cdn.com/v4/letter/l/fbc32d/32.png) [@leemase004](https://discuss.elastic.co/u/leemase004)
#### Post date: [June 24, 2021, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-modules/276949/1 "2021-06-24T14:56:24Z")

</div>

We inherited a cluster and are trying to update the ingest pipeline (ES version 7.6)

Context: When we do GET ingest/pipeline there is a 15k line pipeline. It has all the processors from the filebeat modules they have uploaded: mysql,bro/zeek,suricata,aws,apache,azure etc. (they pretty much put in every single module to provide for future expansion)

1. We are wondering how can we add/adjust one specific module? If there are 5 modules loaded into one specific pipeline: How can we "PUT ingest/Pipeline" and make sure the changes only goes to the Mysql section of the pipeline?

2. Is there a way to cat out all the pipelines that have been created? We run the GET ingest/pipeline and that returns the massive 15k pipeline but we are trying to see if there are other pipelines that have been created.

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [June 25, 2021, 12:16am UTC](https://discuss.elastic.co/t/filebeat-modules/276949/2 "2021-06-25T00:16:23Z")

</div>

You're saying they combined all the module pipelines into one massive one? As for using the api to modify the pipeline, as far as I know it's all or nothing.

---

<div class="post-metadata">

### Author: ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)
#### Post date: [June 25, 2021, 1:45am UTC](https://discuss.elastic.co/t/filebeat-modules/276949/3 "2021-06-25T01:45:03Z")

</div>

My 7.9.2 version of Kibana has "Ingest Node Pipelines" and shows about 70 different pipelines in my stack.

Also, you can do things like

```auto
GET _ingest/pipeline/*apache*

```

In my case, I get 2 filebeat apache pipelines

---

<div class="post-metadata">

### Author: ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)
#### Post date: [June 29, 2021, 10:51am UTC](https://discuss.elastic.co/t/filebeat-modules/276949/4 "2021-06-29T10:51:55Z")

</div>

Correct, when you run Filebeat, it loads all the ingest pipelines for the modules. I guess I'm not understanding your question?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 27, 2021, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-modules/276949/5 "2021-07-27T12:52:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
