# Pipeline not created during setup of packetbeat 8.15.1 on windows

**URL:** <https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [September 17, 2024, 7:46am UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656 "2024-09-17T07:46:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![drops](https://avatars.discourse-cdn.com/v4/letter/d/f4b2a3/32.png) [@drops](https://discuss.elastic.co/u/drops)\
**Post date:** [September 17, 2024, 7:46am UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656/1 "2024-09-17T07:46:50Z")

</div>

{"log.level":"warn","@timestamp":"2024-09-17T09:27:50.421+0200","log.logger":"elasticsearch","log.origin":{"function":"[github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.](http://github.com/elastic/beats/v7/libbeat/outputs/elasticsearch.)(_Client).applyItemStatus","file.name":"elasticsearch/client.go","file.line":489},"message":"Cannot index event '{"@timestamp":"2024-09-17T07:27:50.370Z","type":"flow","source":{"mac":"_ **","ip":"****","port":9200,"packets":23,"bytes":22746},"destination":{"ip":" ****","port":64911,"mac":"** _"},"host":{"architecture":"x86\_64","os":{"name":"Windows 10 Enterprise LTSC 2021","kernel":"10.0.19041.4894 (WinBuild.160101.0800)","build":"19044.4894","type":"windows","platform":"windows","version":"10.0","family":"windows"},"id":"c9667b3f-8413-43ee-baa5-ea2e4194b226","ip":["__**"],"name":"**_","mac":["_**"],"hostname":"**"},"agent":{"ephemeral\_id":"2ce9940c-20ac-498a-a6a6-8042a7eded58","id":"27c13e69-cd60-42e2-9fc3-2b5f6e8ffd81","name":"_\*\*","type":"packetbeat","version":"8.15.1"},"event":{"dataset":"flow","kind":"event","category":["network"],"action":"network\_flow","type":["connection"],"start":"2024-09-17T07:27:20.078Z","end":"2024-09-17T07:27:23.176Z","duration":3097962100},"flow":{"id":"EQQA////DP//////FP8BAAEADCm7oIUAUFaCM8SNNUtWjTVIPfAjj/0","final":false},"network":{"transport":"tcp","community\_id":"1:1mrtWe+jMPKAEBEzwSFCv/2ziLM=","bytes":22746,"packets":23,"type":"ipv4"},"ecs":{"version":"8.0.0"}}\n' (status=400): {"type":"illegal\_argument\_exception","reason":"pipeline with id [packetbeat-8.15.1-routing] does not exist"}, dropping event!","service.name":"packetbeat","log.type":"event","ecs.version":"1.6.0"}

the only two pipelines that are created are:  
packetbeat-8.15.1-default and packetbeat-8.15.1-geoip

Been following the instructions here : [Packetbeat quick start: installation and configuration | Packetbeat Reference [8.15] | Elastic](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-installation-configuration.html)

No errors during setup, index template, dashboards and pipelines according to logs were loaded.

will try an earlier version of packetbeat now...

---

<div class="post-metadata">

**Author:** ![jimB100](https://avatars.discourse-cdn.com/v4/letter/j/a88e4f/32.png) [@jimB100](https://discuss.elastic.co/u/jimB100)\
**Post date:** [October 3, 2024, 10:10am UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656/2 "2024-10-03T10:10:49Z")

</div>

> [@drops](#):
>
> he only two pipelines that are created are:  
> packetbeat-8.15.1-default and packetbeat-8.15.1-geoip

hi @drops , did you get any joy with an earlier version?  
I've tried 8.15.2 which didn't work, i then tried 8.12 also the same problem with it only creating -default and -geoip pipelines on windows

---

<div class="post-metadata">

**Author:** ![drops](https://avatars.discourse-cdn.com/v4/letter/d/f4b2a3/32.png) [@drops](https://discuss.elastic.co/u/drops)\
**Post date:** [October 4, 2024, 10:54am UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656/3 "2024-10-04T10:54:59Z")

</div>

no, unfortunately older versions didnt help me here either. I have had a look at wazuh as a result of that though and am playing with it ever since.

---

<div class="post-metadata">

**Author:** ![jimB100](https://avatars.discourse-cdn.com/v4/letter/j/a88e4f/32.png) [@jimB100](https://discuss.elastic.co/u/jimB100)\
**Post date:** [October 11, 2024, 2:28pm UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656/4 "2024-10-11T14:28:06Z")

</div>

turns out it's a bug in the windows version during the initial implementation. if you run the setup from a linux platform it creates all the pipelines and works a treat. as it only needs to do this once to set everything up, that's what we did, we now have windows clients reporting into elastic.

don't know if that helps, or whether you've already found an alternate way of doing what you were looking at, just thought i'd mention it

> [@Pipeline with id \[packetbeat-8.15.2-routing\] does not exist, dropping event!](https://discuss.elastic.co/t/pipeline-with-id-packetbeat-8-15-2-routing-does-not-exist-dropping-event/368135/12):
>
> packetbeat installed on linux and all working great!

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [October 15, 2024, 5:50pm UTC](https://discuss.elastic.co/t/pipeline-not-created-during-setup-of-packetbeat-8-15-1-on-windows/366656/5 "2024-10-15T17:50:32Z")

</div>

Hey all,

Sorry about the trouble on this one. I believe we identified the problem and merged a fix a couple of weeks ago. It was backported to 8.15 and will be included in the next patch release of 8.15

> <https://github.com/elastic/beats/pull/41110>
>
> Detection of data stream identity was using os.PathSeparator which will not matc…h the path separator used by embed.FS which is always "/"\[1\].
> 
> \[1\]https://pkg.go.dev/embed#hdr-Directives
> 
> \<!-- Type of change
> Please label this PR with one of the following labels, depending on the scope of your change:
> \- Bug
> \- Enhancement
> \- Breaking change
> \- Deprecation
> \- Cleanup
> \- Docs
> \--\>
> 
> \## Proposed commit message
> 
> \<!-- Mandatory
> Explain here the changes you made on the PR.
> 
> Please explain:
> 
> \- WHAT: patterns used, algorithms implemented, design architecture, message processing, etc.
> \- WHY: the rationale/motivation for the changes
> 
> This text will be pasted into the squash dialog when the change is committed and will be
> a long term historical record of the change to help future contributors understand the
> change, please help them by making it clear and comprehensive, they may be you.
> 
> If the commit title is adequate to describe both of these things, The text here may be omitted
> or replaced with "See title". The title of the PR will be used as the commit message title when
> the merge is made and the "See title" marker will be removed if present.
> 
> The text here and the PR title will be subject to the PR review process.
> \--\>
> 
> \## Checklist
> 
> \<!-- Mandatory
> Add a checklist of things that are required to be reviewed in order to have the PR approved
> 
> List here all the items you have verified BEFORE sending this PR. Please DO NOT remove any item, striking through those that do not apply. (Just in case, strikethrough uses two tildes. ~~Scratch this.~~ )
> \--\>
> 
> \- \[\] My code follows the style guidelines of this project
> \- \[\] I have commented my code, particularly in hard-to-understand areas
> \- \[\] I have made corresponding changes to the documentation
> \- \[\] I have made corresponding change to the default configuration files
> \- \[\] I have added tests that prove my fix is effective or that my feature works
> \- \[\] I have added an entry in \`CHANGELOG.next.asciidoc\` or \`CHANGELOG-developer.next.asciidoc\`.
> 
> \## Disruptive User Impact
> 
> \<!--
> Will the changes introduced by this PR cause disruption to users in any way? If so, please describe what changes users
> could make on their end to nullify or minimize this disruption. Consider impacts in related systems, not just directly
> when using Beats.
> \--\>
> 
> \## Author's Checklist
> 
> \<!-- Recommended
> Add a checklist of things that are required to be reviewed in order to have the PR approved
> \--\>
> \- \[\]
> 
> \## How to test this PR locally
> 
> \<!-- Recommended
> Explain here how this PR will be tested by the reviewer: commands, dependencies, steps, etc.
> \--\>
> 
> \## Related issues
> 
> \<!-- Recommended
> Link related issues below. Insert the issue link or reference after the word "Closes" if merging this should automatically close it.
> 
> \- Closes #123
> \- Relates #123
> \- Requires #123
> \- Superseds #123
> \--\>
> \-
> 
> \## Use cases
> 
> \<!-- Recommended
> Explain here the different behaviors that this PR introduces or modifies in this project, user roles, environment configuration, etc.
> 
> If you are familiar with Gherkin test scenarios, we recommend its usage: https://cucumber.io/docs/gherkin/reference/
> \--\>
> 
> \## Screenshots
> 
> \<!-- Optional
> Add here screenshots about how the project will be changed after the PR is applied. They could be related to web pages, terminal, etc, or any other image you consider important to be shared with the team.
> \--\>
> 
> \## Logs
> 
> \<!-- Recommended
> Paste here output logs discovered while creating this PR, such as stack traces or integration logs, or any other output you consider important to be shared with the team.
> \--\>
