# How can I easily convert logstash filters with grok to ingest pipelines?

**URL:** <https://discuss.elastic.co/t/how-can-i-easily-convert-logstash-filters-with-grok-to-ingest-pipelines/119704>\
**Category:** Elasticsearch\
**Created:** [February 13, 2018, 7:57pm UTC](https://discuss.elastic.co/t/how-can-i-easily-convert-logstash-filters-with-grok-to-ingest-pipelines/119704 "2018-02-13T19:57:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ujjain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ujjain/32/27378_2.png) [@ujjain](https://discuss.elastic.co/u/ujjain)\
**Post date:** [February 13, 2018, 7:57pm UTC](https://discuss.elastic.co/t/how-can-i-easily-convert-logstash-filters-with-grok-to-ingest-pipelines/119704/1 "2018-02-13T19:57:40Z")

</div>

Logstash has ingest-convert.sh to convert ingest pipelines to Logstash, but I'd like to convert the other way around.

I have the 23-Tomcat-filters and grok\_patterns file.

Is there any smart way that would save me time writing all json files to this ingest pipeline-format, based on the current logstash configuration?

```
PUT _ingest/pipeline/ujjain
{
  "description" : "Pipeline ujjain",
  "processors": [
    {
      "grok": {
        "field": "message",
        "patterns": ["%{MONTH}%{SPACE}%{MONTHDAY},%{SPACE}%{YEAR}%{SPACE}%{HOUR}:?%{MINUTE}(?::?%{SECOND})%{SPACE}(?:AM|PM)%{SPACE}%{NOTSPACE:class}%{SPACE}%{NOTSPACE:type_log}%{SPACE}%{WORD:loglevel}:%{SPACE}%{GREEDYDATA:log_text}"]
    }

```

...

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [February 15, 2018, 2:23am UTC](https://discuss.elastic.co/t/how-can-i-easily-convert-logstash-filters-with-grok-to-ingest-pipelines/119704/2 "2018-02-15T02:23:09Z")

</div>

If you already have them in Logstash, why do you want to migrate back to ingest pipelines?

Ingest node was thought as an initial step to get log parsing working without the requirement of running Logstash if you are just doing simple parsing.

Hence, there is no real gain to migrate back to ingest pipelines if you already have Logstash working.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 15, 2018, 6:17am UTC](https://discuss.elastic.co/t/how-can-i-easily-convert-logstash-filters-with-grok-to-ingest-pipelines/119704/3 "2018-02-15T06:17:49Z")

</div>

[This blog post](https://www.elastic.co/blog/should-i-use-logstash-or-elasticsearch-ingest-nodes) discusses the differences in capabilities between Logstash and ingest nodes. Logstash has more functionality, so it would help to see your existing config to judge if it would be possible to implement this efficiently as ingest node pipelines or not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2018, 6:18am UTC](https://discuss.elastic.co/t/how-can-i-easily-convert-logstash-filters-with-grok-to-ingest-pipelines/119704/4 "2018-03-15T06:18:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
