# How to obtain mappings and ingest pipelines from Elastic integrations without using Fleet?

**URL:** <https://discuss.elastic.co/t/how-to-obtain-mappings-and-ingest-pipelines-from-elastic-integrations-without-using-fleet/378408>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [May 22, 2025, 8:34am UTC](https://discuss.elastic.co/t/how-to-obtain-mappings-and-ingest-pipelines-from-elastic-integrations-without-using-fleet/378408 "2025-05-22T08:34:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [May 22, 2025, 8:34am UTC](https://discuss.elastic.co/t/how-to-obtain-mappings-and-ingest-pipelines-from-elastic-integrations-without-using-fleet/378408/1 "2025-05-22T08:34:55Z")

</div>

We’re working on ingesting logs from network devices (e.g., Cisco IOS) that send their logs via **Syslog** directly to **Logstash** , which then forwards the data to Elasticsearch. We manage all components through **custom automation (e.g., Ansible)** — **without using Elastic Agent or Fleet Server**.

For operational and security reasons, we want to avoid using Fleet and Elastic Agent, mainly due to concerns about vendor lock-in.

We would like to make use of official Elastic integrations from GitHub:  
[integrations/packages/cisco\_ios at main · elastic/integrations · GitHub](https://github.com/elastic/integrations/tree/main/packages/cisco_ios)

And extract from them:  
• ✅ index mappings (without requiring Fleet or Elastic Agent)

### **What we’ve tried:**

We took the fields.yml from the integration: [https://github.com/elastic/integrations/blob/main/packages/cisco\_ios/data\_stream/log/fields/fields.yml](https://github.com/elastic/integrations/blob/main/packages/cisco_ios/data_stream/log/fields/fields.yml)

Then attempted to generate ECS-compliant mappings using the ECS generator: [https://github.com/elastic/ecs](https://github.com/elastic/ecs)

We placed the fields.yml into usage-example/fields/custom/, created a custom subset.yml, and manually added missing attributes like level and description. We ran the generator with:

```auto
python3 scripts/generator.py \
  --ref v8.0.0 \
  --include usage-example/fields/custom/ \
  --subset usage-example/fields/subset.yml \
  --out output2/ \
  --template-settings-legacy usage-example/fields/template-settings-legacy.json \
  --template-settings usage-example/fields/template-settings.json \
  --mapping-settings usage-example/fields/mapping-settings.json \
  --semconv-version v1.23.0

```

However, we ran into multiple validation errors like:

```auto
ValueError: Field is missing the following mandatory attributes: description.

```

Even after adding level, description, etc., the generator continues to fail. It seems that the fields.yml from integrations is **not directly compatible** with the ECS schema generator.

### **❓ Questions**

1. Is it officially supported or recommended to extract and apply the index\_template/default.yml and ingest\_pipeline/default.yml from an integration package via API (PUT \_index\_template, PUT \_ingest/pipeline)?
2. Is there an official tool or supported method to extract only the ingest pipeline and mappings from an Elastic integration **without using Fleet**?
3. If we don’t want to use Elasticsearch ingest nodes, but process everything via **Logstash** , is there any way to get or convert the integration’s ingest pipeline into a Logstash pipeline format (e.g., filter { ... })?

Our goals are:  
• ✅ No Fleet or Elastic Agent  
• ✅ Full control via automation (e.g., Ansible)  
• ✅ **Manual setup of index templates**  
• ✅ **Prefer using Logstash instead of ingest nodes, ideally with ready-to-use pipeline definitions (e.g., grok, date, etc.) — without manually extracting or rewriting them from ingest pipelines**

Thanks in advance for your help or guidance!

**— Václav Šulc**

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [May 29, 2025, 12:00pm UTC](https://discuss.elastic.co/t/how-to-obtain-mappings-and-ingest-pipelines-from-elastic-integrations-without-using-fleet/378408/2 "2025-05-29T12:00:01Z")

</div>

I ran into the built-in ingest-convert.sh helper in Logstash 8.17.4:

```auto
bin/ingest-convert.sh \
  --input /tmp/ingest-pipeline.json \
  --output /tmp/logstash.conf

```

and tried it on the Cisco-IOS integration’s ingest pipeline. Unfortunately I keep hitting a NullPointerException (missing value\_contents) during conversion—looks like some processors (inline pattern\_definitions, empty fields) aren’t directly supported. I’m in the process of stripping out those unsupported bits (e.g. inline Grok patterns and null-valued params) to get a clean logstash.conf. Any pointers on handling those edge cases?
