# Ingestion Pipeline not parsing out field values

**URL:** <https://discuss.elastic.co/t/ingestion-pipeline-not-parsing-out-field-values/122285>\
**Category:** Elasticsearch\
**Created:** [March 2, 2018, 3:12pm UTC](https://discuss.elastic.co/t/ingestion-pipeline-not-parsing-out-field-values/122285 "2018-03-02T15:12:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tonyz](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tonyz](https://discuss.elastic.co/u/tonyz)\
**Post date:** [March 2, 2018, 3:12pm UTC](https://discuss.elastic.co/t/ingestion-pipeline-not-parsing-out-field-values/122285/1 "2018-03-02T15:12:27Z")

</div>

Hi,

I am applying a new ingestion pipeline through Kibana Dev Tools to parse a specific field. However, when I created the pipeline the fields are not parsed out at all. I tried this in \_ingest/pipeline/\_simulate before submitting the put pipeline API and it works in simulate.

Below is my ingest pipeline.

```
  PUT _ingest/pipeline/1
{
    "description": "parse json object",
    "processors": [
      {

        "grok": {
          "field": "log",
          "patterns": [
            "%{RUBY_LOGGER}\\[%{BACULA_JOB:job}\\]%{GREEDYDATA:log}"
          ],
          "ignore_failure":true
        },
        "json": {
          "field": "log",
          "target_field": "log-json",
          "ignore_failure": true
        }
        }
      
    ]
}

```

\_ingest/pipeline/\_simulate

```
POST _ingest/pipeline/_simulate
    {
      "pipeline": {
        "description": "parse json object",
        "processors": [
          {

            "grok": {
              "field": "log",
              "patterns": [
                "%{RUBY_LOGGER}\\[%{BACULA_JOB:job}\\]%{GREEDYDATA:log}"
              ],
              "ignore_failure":true
            },
            "json": {
              "field": "log",
              "target_field": "log-json",
              "ignore_failure": true
            }
            }
          
        ]
      },
      "docs": [
        {
          "_source": {
            "log": "I, [2018-03-02T14:37:24.048385 #7] INFO -- : [96621855-c4f1-4c8e-b9c9-2bbb4e50171c]{\"key\":\"value\",\"key2\":\"value2\",\"key3\":1,\"key4\":1,\"key5\":1,\"key6\":\"value\"}\n"
          }
        }
      ]
    }

```

Any guidance would be greatly appreciated.

Thanks,  
Tony

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2018, 3:12pm UTC](https://discuss.elastic.co/t/ingestion-pipeline-not-parsing-out-field-values/122285/2 "2018-03-30T15:12:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
