# Ingest Pipeline for custom logs

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380>\
**Category:** Elastic Agent\
**Created:** [December 2, 2022, 2:43pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380 "2022-12-02T14:43:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [December 2, 2022, 2:43pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/1 "2022-12-02T14:43:57Z")

</div>

Hi,  
I am ingesting the standards syslogs using the elastic agent "custom logs" integration. I am trying to parse the logs before indexing and for that I am using ingest pipeline. I have two processors for that: Grok and remove in a sequential manner. When I test the pipeline in ingest pipeline it works but when I use in the custom log integration in the section custom configurations:  
`pipeline:example-ingest-pipeline` and save and deploy the integration it throws error like this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/6/8650049c5cc7da26b9010bc755c61bf0a06bfd64.png)

Does anybody have idea on this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 2, 2022, 3:12pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/2 "2022-12-02T15:12:57Z")

</div>

Did you try putting a space after the `:`  
`pipeline: example-ingest-pipeline`

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [December 2, 2022, 3:41pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/3 "2022-12-02T15:41:36Z")

</div>

@stephenb yes, I missed the space after pipeline. Error goes away but still pipeline is not integrated. I will update things how it goes. Thank you for the immediate response.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 2, 2022, 3:49pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/4 "2022-12-02T15:49:20Z")

</div>

Can you show the screenshot of where you put that in.

You're using the custom logs integration?

That should work. I used that all the time.

Did you put any error handling in to see if it's failing in the ingest pipeline?

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [December 5, 2022, 11:59am UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/5 "2022-12-05T11:59:02Z")

</div>

@stephenb Yes, it works. I just had to redo the integration and ingest pipeline. It wasn't working probably working because I was editing the the integration and pipeline. Thank you, now it works like a charm.

---

<div class="post-metadata">

**Author:** ![shuuny-matrix](https://avatars.discourse-cdn.com/v4/letter/s/7993a0/32.png) [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Post date:** [December 7, 2022, 5:19pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/6 "2022-12-07T17:19:28Z")

</div>

Hi @stephenb, now I could parse data and everything looks good. however, there is still one caveat - I can't run the KQL queries in Discover as it shows like this:

 ![query](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5054461b2a939027f5238a97460a8869cd11d1f.png)

My KQL queries run perfectly fine when I am ingesting data without the ingest pipeline via custom logs integration

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 7, 2022, 5:42pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/7 "2022-12-07T17:42:37Z")

</div>

What is the KQL Query .. what does the document Look Like

The KQL is probably not returning any results / no match

What does your documents look like and what exact KQL... need exact Examples

> [@shuuny-matrix](#):
>
> My KQL queries run perfectly fine when I am ingesting data without the ingest pipeline via custom logs integration

The ingest pipeline is creating different fields look at the documents / mappings ... more details otherwise we are just guessing

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2023, 5:42pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380/8 "2023-01-04T17:42:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
