# How to specify pipelines.yml file path

**URL:** <https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923>\
**Category:** Logstash\
**Created:** [August 10, 2021, 11:56am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923 "2021-08-10T11:56:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 10, 2021, 11:56am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/1 "2021-08-10T11:56:38Z")

</div>

I'm working on Logstash setup in a legacy system with no owners in the organisation.  
Using `ps`, i found the process executing the logstash service:

```auto
/usr/bin/java -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -Djava.awt.headless=true -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+HeapDumpOnOutOfMemoryError -Djava.io.tmpdir=/var/lib/logstash -Xmx1g -Xss2048k -Djffi.boot.library.path=/opt/logstash/vendor/jruby/lib/jni -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -Djava.awt.headless=true -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+HeapDumpOnOutOfMemoryError -Djava.io.tmpdir=/var/lib/logstash -XX:HeapDumpPath=/opt/logstash/heapdump.hprof -Xbootclasspath/a:/opt/logstash/vendor/jruby/lib/jruby.jar -classpath : -Djruby.home=/opt/logstash/vendor/jruby -Djruby.lib=/opt/logstash/vendor/jruby/lib -Djruby.script=jruby -Djruby.shell=/bin/sh org.jruby.Main --1.9 /opt/logstash/lib/bootstrap/environment.rb logstash/runner.rb agent -f /etc/logstash/conf.d -l /var/log/logstash/logstash.log

```

I know the config file being used in the logstash service -\> `/etc/logstash/conf.d/ls.conf`.

But I want to modify the service to use forked pipelines. But what I assume is the home dir ... `/opt/logstash` doesn't contain any `logstash.yml` or `pipelines.yml`.  
How do I restart the service to use the `pipelines.yml` I've written?

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 11, 2021, 2:18am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/2 "2021-08-11T02:18:24Z")

</div>

An update: `/opt/logstash/bin/logstash --version` says v2.2.4

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 11, 2021, 2:30am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/3 "2021-08-11T02:30:45Z")

</div>

It is not possible, version `2.2.4` has no support to multiple pipelines (which is configured through `pipelines.yml`).

The multiple pipelines was introduced only in version `6.0`.

The only way to use multiple pipelines is to upgrade to a newer version, which you should do as soon as possible as `2.2.X` reached EOL in 2017.

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 11, 2021, 2:32am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/4 "2021-08-11T02:32:29Z")

</div>

Thanks for responding. I'm afraid of all the breaking changes from upgrading to +5 versions.

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 11, 2021, 2:37am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/5 "2021-08-11T02:37:46Z")

</div>

Also, how to find the .sincedb for 2.2.4?

How to plan for the upgrade? I'm reading a ../.\*txt input using filebeat + logstash.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 11, 2021, 2:46am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/6 "2021-08-11T02:46:20Z")

</div>

> [@GitSpree23](#):
>
> I'm afraid of all the breaking changes

Working with the Elastic stack and being afraid of breaking changes is not a good match 😆 Elastic have no fear of introducing breaking changes when they think it provides enough benefit. That said, I realize you have been given a task to complete.

What are you trying to do with multiple pipelines? The distributor and collector patterns can be implemented in a single pipeline using if-else blocks in the filter and/or output sections. A forked-path pattern can be implemented using a clone filter plus an if-else based on the type added by the clone filter.

The output-isolator pattern cannot be implemented in old versions.

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 11, 2021, 2:52am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/7 "2021-08-11T02:52:06Z")

</div>

I'm working with a single input source (file path =\> "/abc/.\*txt") but want to use two different filter plugins for 2 different outputs - in the future I'm gonna downgrade the RabbitMQ output & persist the Kafka output. So I want to implement a forked path.

I should upgrade the system since we're doing an architecture overhaul of the downstream application anyway. Just that I don't know what to tick off before upgrading. I think I should read the sincedb and provide the path in the new installation, but I can't find a '_sincedb_' anywhere in the system!

---

<div class="post-metadata">

**Author:** ![GitSpree23](https://avatars.discourse-cdn.com/v4/letter/g/65b543/32.png) [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Post date:** [August 11, 2021, 3:20am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/8 "2021-08-11T03:20:18Z")

</div>

Update: Filebeat is actually reading the input & using 0.0.0.0:5044 as Logstash output. And it's v7.8.

If I stop the Logstash service, will I lose events from Filebeat. Or will the last read checkpoint be persisted and read by the new Logstash?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2021, 3:20am UTC](https://discuss.elastic.co/t/how-to-specify-pipelines-yml-file-path/280923/9 "2021-09-08T03:20:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
