# Ingest pipelines: logstash equivalent template for winlogbeat security

**URL:** <https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634>\
**Category:** Logstash\
**Created:** [May 16, 2024, 2:20pm UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634 "2024-05-16T14:20:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 16, 2024, 2:20pm UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/1 "2024-05-16T14:20:48Z")

</div>

Hello,

I've just found that there are Ingest Pipelines and I was wondering if there is an equivalent template for logstash or maybe if you know how to convert it to logstash format ?

It would be useful especially for the windows security logs 🙂

**e.g:** The last processor of the winlogbeat security ingest pipeline is removing the field `event.original`, I know how to translate this action in logstash format but for the other processors its look difficult to find the equivalent.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/3/03b918a2a13dbe49dc40c61a510cecfe524ad278.png)

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 16, 2024, 2:24pm UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/2 "2024-05-16T14:24:36Z")

</div>

Actually there is a tool ! [Converting Ingest Node Pipelines | Logstash Reference [8.13] | Elastic](https://www.elastic.co/guide/en/logstash/current/ingest-converter.html)

Sorry for my dumb question ! Next time i will RTFM ^^

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2024, 3:04pm UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/3 "2024-05-16T15:04:57Z")

</div>

> [@s0p4L1n3](#):
>
> Actually there is a tool !

True, but it looks like it hasn't been [updated](https://github.com/elastic/logstash/tree/main/tools/ingest-converter/src/main/java/org/logstash/ingest) in four years, so I would not be surprised if it is unable to do the conversion on some (much?) of the functionality that has been added to ingest pipelines since then.

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 17, 2024, 6:54am UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/4 "2024-05-17T06:54:35Z")

</div>

Yes I just saw that, especially that the Winlogbeat ingest pipelines has many scripts processors and the tool is unable to convert it.

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 17, 2024, 8:13am UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/5 "2024-05-17T08:13:57Z")

</div>

Yep, it seems not to work I have an exception:

```auto
bin/ingest-convert.sh --input file:///usr/share/logstash/pipeline/winlogbeat/winlogbeat-8.13.2-security.json --output file:///usr/share/logstash/pipeline/winlogbeat/winlog-security-parser.conf
Exception in thread "main" java.lang.NullPointerException: Cannot invoke "java.util.List.stream()" because "processors" is null
        at org.logstash.ingest.IngestPipeline.toLogstash(IngestPipeline.java:44)
        at org.logstash.ingest.JsUtil.convert(JsUtil.java:165)
        at org.logstash.ingest.Pipeline.main(Pipeline.java:35)

```

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 22, 2024, 6:52am UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/6 "2024-05-22T06:52:00Z")

</div>

Hello, I found an alternative to convert the painless scripts which are difficult to me as I'm not a developer..

I used chatgpt to convert the painless script Kerberos Ticket Options from winlogbeat-security Ingest pipelines.

Here's the details, my questions are in french but you can translate, what's important is the result and it can convert easily to a logstash format 👍

[https://chatgpt.com/share/c3fe2c6c-db73-4e50-821f-3fec92be2d71](https://chatgpt.com/share/c3fe2c6c-db73-4e50-821f-3fec92be2d71)

It even explain each steps on how it works ! the same method can be used to convert all other painless scripts

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 22, 2024, 7:58am UTC](https://discuss.elastic.co/t/ingest-pipelines-logstash-equivalent-template-for-winlogbeat-security/359634/7 "2024-05-22T07:58:15Z")

</div>

Merci !

Thanks for sharing.
