# Logstash ingest pipeline at elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-ingest-pipeline-at-elasticsearch/146322>\
**Category:** Logstash\
**Created:** [August 28, 2018, 10:46am UTC](https://discuss.elastic.co/t/logstash-ingest-pipeline-at-elasticsearch/146322 "2018-08-28T10:46:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [August 28, 2018, 10:46am UTC](https://discuss.elastic.co/t/logstash-ingest-pipeline-at-elasticsearch/146322/1 "2018-08-28T10:46:54Z")

</div>

Hi All

i m trying to use the filebeat -\> logstash -\> elasticsearch flow. When i enable the system module from filebeat the message doesn't parse so trying to use the output.elasticsearch pipeline option is not working.

## ERROR

```auto
[2018-08-28T12:03:58,390][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"fileb
eat-6.2.4-2018.08.28", :_type=>"doc", :_routing=>nil, :pipeline=>"filebeat-6.2.4-system-syslog-pipeline"}, #<LogStash::Event:0xd3ae967>], :response=>{"index"=>{"_index"=>"filebeat-6.2.4-2018.08.
28", "_type"=>"doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"pipeline with id [filebeat-6.2.4-system-syslog-pipeline] does not exist"}}}}

```

**Configuration**

```auto
input {
  beats {
    port => 5044
   
  }
}
output {
  elasticsearch {
   hosts => "http://ese0001:9200"
   index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
   pipeline => "%{filebeat-6.2.4-system-syslog-pipeline}"
 }
}

```

---

<div class="post-metadata">

**Author:** ![\_Alex](https://avatars.discourse-cdn.com/v4/letter/_/54ee81/32.png) [@\_Alex](https://discuss.elastic.co/u/_Alex)\
**Post date:** [August 28, 2018, 11:11am UTC](https://discuss.elastic.co/t/logstash-ingest-pipeline-at-elasticsearch/146322/2 "2018-08-28T11:11:23Z")

</div>

Index and pipeline are both expecting strings. Here when you say `"%{filebeat-6.2.4-system-syslog-pipeline}"` this is looking for a variable called `filebeat-6.2.4-system-syslog-pipeline` which doesn't exist. If you remove the percentage signs from everything that's not a variable you should be OK.

```
output {
  elasticsearch {
   hosts => "http://ese0001:9200"
   index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
   pipeline => "filebeat-6.2.4-system-syslog-pipeline"
 }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2018, 11:11am UTC](https://discuss.elastic.co/t/logstash-ingest-pipeline-at-elasticsearch/146322/3 "2018-09-25T11:11:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
