# "Pipeline does not exist" issue with sonicwall filebeat module

**URL:** <https://discuss.elastic.co/t/pipeline-does-not-exist-issue-with-sonicwall-filebeat-module/271067>\
**Category:** Logstash\
**Tags:** ingest-pipeline\
**Created:** [April 23, 2021, 9:59am UTC](https://discuss.elastic.co/t/pipeline-does-not-exist-issue-with-sonicwall-filebeat-module/271067 "2021-04-23T09:59:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tony51](https://avatars.discourse-cdn.com/v4/letter/t/9de053/32.png) [@Tony51](https://discuss.elastic.co/u/Tony51)\
**Post date:** [April 23, 2021, 9:59am UTC](https://discuss.elastic.co/t/pipeline-does-not-exist-issue-with-sonicwall-filebeat-module/271067/1 "2021-04-23T09:59:50Z")

</div>

Hi,  
I'm sending logs from filebeat to logstash but it I'm getting this error from logstash connecting to elastisearch:

```auto
[2021-04-20T10:50:47,200][WARN][logstash.outputs.elasticsearch][main] 673b0cb9e015302058e251f502b8] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"filebeat-7.12.0-2021.04.23", :routing=>nil, :_type=>"_doc", :pipeline=>"filebeat-7.12.0-sonicwall-firewall-pipeline"}, #<LogStash::Event:0x591409f5>], :response=>{"index"=>{"_index"=>"filebeat-7.12.0-2021.04.23", "_type"=>"_doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"pipeline with id [filebeat-7.12.0-sonicwall-firewall-pipeline] does not exist"}}}}

```

I don't understand why filebeat doesn't create the pipeline with setup command :  
`sudo filebeat setup --pipelines --modules sonicwall`

When I run `GET _ingest/pipeline/filebeat-7.12.0-*` I only get pipelines from cisco :

```auto
   "filebeat-7.12.0-cisco-ios-pipeline" :{...}
   "filebeat-7.12.0-cisco-amp-pipeline" :{...}
    ...

```

Here my logstash conf :

```auto
input {
      beats {
        port => 5044
      }
    }
    output {
      if [@metadata][pipeline] {
        elasticsearch {
        hosts => ["localhost:9200"]
        manage_template => false
        index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
        pipeline => "%{[@metadata][pipeline]}"
        }
      } else {
        elasticsearch {
        hosts => ["localhost:9200"]
        manage_template => false
        index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
        }
      }
     stdout{ codec => rubydebug }
    }

```

It's been several days since I try to find an answer but nothing... So please can someone help me understand

Regards,

---

<div class="post-metadata">

**Author:** ![Tony51](https://avatars.discourse-cdn.com/v4/letter/t/9de053/32.png) [@Tony51](https://discuss.elastic.co/u/Tony51)\
**Post date:** [May 3, 2021, 12:41pm UTC](https://discuss.elastic.co/t/pipeline-does-not-exist-issue-with-sonicwall-filebeat-module/271067/2 "2021-05-03T12:41:21Z")

</div>

Hey, my problem is solve in a certain way...

To resolve this issue, I modify my filebeats conf to export data directly to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 12:42pm UTC](https://discuss.elastic.co/t/pipeline-does-not-exist-issue-with-sonicwall-filebeat-module/271067/3 "2021-05-31T12:42:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
