# Filebeat pipelines

**URL:** <https://discuss.elastic.co/t/filebeat-pipelines/177238>\
**Category:** Beats\
**Created:** [April 17, 2019, 8:47am UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238 "2019-04-17T08:47:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 17, 2019, 8:47am UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/1 "2019-04-17T08:47:01Z")

</div>

Hi,  
Is it possible to customise the naming of pipelines used by filebeat. Is there any example config?

Regards,  
D

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 17, 2019, 4:38pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/2 "2019-04-17T16:38:41Z")

</div>

To use an Ingest Pipeline with Filebeat, you would first create that Ingest Pipeline in Elasticsearch and then reference it in your `filebeat.yml` configuration file, via the `output.elasticsearch.pipeline` setting. Since you create the Ingest Pipeline in Elasticsearch, you can name it whatever you want.

Read more about using Ingest Pipelines in Filebeat here: [https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html).

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 17, 2019, 7:06pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/3 "2019-04-17T19:06:28Z")

</div>

Ok thanks. Let's say I have a pipeline uploaded with a custom name and then decided to ship via logstash, how do I set the correct pipeline name in the filebeat metadata?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 17, 2019, 9:12pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/4 "2019-04-17T21:12:57Z")

</div>

If you are shipping from Filebeat -\> Logstash -\> ES (running Ingest pipeline), why do you need to specify the Ingest pipeline name in Filebeat? Why not just specify it in the `elasticsearch` output configuration in your Logstash pipeline, via the `pipeline` setting: [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-pipeline](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-pipeline)?

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 18, 2019, 8:29am UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/5 "2019-04-18T08:29:08Z")

</div>

That's what I'm doing via metadata @shaunak. So, I need to be sure that the pipeline metadata sent via filebeat matches the custom pipeline name in elasticsearch.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 18, 2019, 4:38pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/6 "2019-04-18T16:38:49Z")

</div>

I'm not sure you can do it via the `@metadata` field. But you could add a custom field with your pipeline name in it using either the [`fields` setting](https://www.elastic.co/guide/en/beats/filebeat/7.0/configuration-general-options.html#libbeat-configuration-fields) or the [`add_fields` processor](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html), and then reference it in your Logstash pipeline configuration.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [April 21, 2019, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/7 "2019-04-21T15:56:33Z")

</div>

Well, the index name can be specified so it's rather surprising that the pipeline name can't be overridden too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2019, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-pipelines/177238/8 "2019-05-19T17:56:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
