# Grok Ingest Pipeline and the Elastic Common Schema

**URL:** <https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [September 8, 2020, 5:06pm UTC](https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917 "2020-09-08T17:06:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![roshanp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roshanp/32/4108_2.png) [@roshanp](https://discuss.elastic.co/u/roshanp)\
**Post date:** [September 8, 2020, 5:06pm UTC](https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917/1 "2020-09-08T17:06:54Z")

</div>

Hi there,

I want to use the Grok patterns already available in the Elastic Ingest pipeline; however, I don't see how I can map the default field names provided to the Elastic common schema? Is there any work towards that currently? I have seen a bunch of articles about using custom Grok with ECS, but not using the patterns already available. Not sure if I missed something obvious.

Roshan

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [September 8, 2020, 10:32pm UTC](https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917/2 "2020-09-08T22:32:27Z")

</div>

I think an example might help, what existing ingest pipeline? What version of Elastic?

---

<div class="post-metadata">

**Author:** ![roshanp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roshanp/32/4108_2.png) [@roshanp](https://discuss.elastic.co/u/roshanp)\
**Post date:** [September 9, 2020, 10:05am UTC](https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917/3 "2020-09-09T10:05:55Z")

</div>

Hey sorry for the lack of details.

I was just looking at the code to see if it was possible first for our project: [https://github.com/elastic/elasticsearch/blob/master/libs/grok/src/main/resources/patterns/bro](https://github.com/elastic/elasticsearch/blob/master/libs/grok/src/main/resources/patterns/bro).

We are trying to ingest BRO data, and I was hoping to use the GrokParser. However, I noticed that the fields are mapping to a custom field name that is not compatible with ECS. For example, I was expecting the `resp_h` field to be `destination.ip` from ECS, [https://www.elastic.co/guide/en/ecs/current/ecs-destination.html](https://www.elastic.co/guide/en/ecs/current/ecs-destination.html).

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [September 9, 2020, 2:11pm UTC](https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917/4 "2020-09-09T14:11:42Z")

</div>

There seems to be doc [https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-zeek.html)

destination.ip is a ECS common field. Looking at the date of that github repo, its from Feb 2018. There is a filebeat Zeek module [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-zeek.html)

Are you using filebeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2020, 2:11pm UTC](https://discuss.elastic.co/t/grok-ingest-pipeline-and-the-elastic-common-schema/247917/5 "2020-10-07T14:11:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
