# Ingest\_pipeline - Elastic Cloud

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 24, 2021, 8:19am UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175 "2021-03-24T08:19:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![evgeniy777](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy777/32/85978_2.png) [@evgeniy777](https://discuss.elastic.co/u/evgeniy777)\
**Post date:** [March 24, 2021, 8:19am UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175/1 "2021-03-24T08:19:00Z")

</div>

Hi all !

i'm using Elastic Cloud solution and FileBeat on my servers.  
made a simple **ingest\_pipeline** for parsing my custom app logs.  
On Filebeat config i'm defining "cloud.auth:" and "cloud.id:", but i don't know how to set the pipeline for my data ?

```auto
cloud.auth: bla bla
cloud.id: blabla
output.elasticsearch:
  pipeline: "pipeline_name" 

```

this not working - i got data, but it's not going throught pipeline to be parsed.  
Maybe i have to define a pipeline in some other way ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 29, 2021, 1:43pm UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175/2 "2021-03-29T13:43:45Z")

</div>

Welcome!

I think this is the correct way.

Unless there's a recent issue, I was doing the same thing in the past: [bano-elastic/filebeat-all.yml at master · dadoonet/bano-elastic · GitHub](https://github.com/dadoonet/bano-elastic/blob/master/filebeat-config/filebeat-all.yml)

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /bano-data/bano-*.csv

output.elasticsearch:
  indices:
    - index: "bano-foo"
  pipeline: bano

```

And: [bano-elastic/filebeat.sh at master · dadoonet/bano-elastic · GitHub](https://github.com/dadoonet/bano-elastic/blob/master/filebeat.sh)

```auto
	docker run \
	  --name=filebeat \
	  --user=root \
	  --volume="$(pwd)/bano-data:/bano-data:ro" \
	  --volume="$(pwd)/filebeat-config/filebeat$FILEBEAT_CONFIG_SUFFIX.yml:/usr/share/filebeat/filebeat.yml" \
	  -p 8000:8000 \
	  docker.elastic.co/beats/filebeat:$ELASTIC_VERSION filebeat -e -strict.perms=false -d "$FILEBEAT_SELECTORS" -E cloud.id="$CLOUD_ID" -E cloud.auth="elastic:$ELASTIC_PASSWORD"

```

Which is quite similar...

I moved your question to #elastic-stack:beats.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 29, 2021, 2:57pm UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175/3 "2021-03-29T14:57:06Z")

</div>

Hi @evgeniy777 welcome to the community

Couple things ...

1. Have you tested the pipeline outside of filebeat in Kibana / Dev Tools. Setup the pipeline then try to index a document in Dev Tools to validate the pipeline is actually working?

2. Are you using a module? or specific Input if so sometimes there are default pipelines that overrides yours unless you config correctly.

Let us know these 2 things and perhaps we can help more.

---

<div class="post-metadata">

**Author:** ![evgeniy777](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy777/32/85978_2.png) [@evgeniy777](https://discuss.elastic.co/u/evgeniy777)\
**Post date:** [April 7, 2021, 10:46am UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175/4 "2021-04-07T10:46:55Z")

</div>

1 - yes it's working.

Actually i don't define a pipeline name in "filebeat.yml", i updated an index.template in Kibana with "index.default\_pipeline" :

```auto
default_pipeline": "pipeline_1",

```

So when new index is created and match the template - it's start automatically going throught " index.default\_pipeline ". Now it's working fine.

Thanks for helping guys !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2021, 10:47am UTC](https://discuss.elastic.co/t/ingest-pipeline-elastic-cloud/268175/5 "2021-05-05T10:47:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
