# Pipeline Output Filter not accepting existing fields from an event as parameter

**URL:** <https://discuss.elastic.co/t/pipeline-output-filter-not-accepting-existing-fields-from-an-event-as-parameter/194899>\
**Category:** Logstash\
**Created:** [August 12, 2019, 6:22pm UTC](https://discuss.elastic.co/t/pipeline-output-filter-not-accepting-existing-fields-from-an-event-as-parameter/194899 "2019-08-12T18:22:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [August 12, 2019, 6:22pm UTC](https://discuss.elastic.co/t/pipeline-output-filter-not-accepting-existing-fields-from-an-event-as-parameter/194899/1 "2019-08-12T18:22:18Z")

</div>

Hi,

Im trying out pipeline-to-pipeline connections ([https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html](https://www.elastic.co/guide/en/logstash/current/pipeline-to-pipeline.html)), and apparently the output filter does not recognize existing fields of an event as a parameter.

```
# if fields.docType exists, send to pipeline "{fields.docType}", else send to pipeline "default"
   output {
      if [fields][docType] {
        pipeline { send_to => "%{[fields][docType]}" }
      } else {
        pipeline { send_to => default }
      }
    }

```

It still goes to the "default" pipeline even fields.docType(="RSA SecOps") exists in the event, and pipeline "RSA SecOps" exists in Logstash.  
Please advise if that is even feasible to have dynamic parameter for "send\_to" param in pipeline filter. Thanks.

Perry

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 6:40pm UTC](https://discuss.elastic.co/t/pipeline-output-filter-not-accepting-existing-fields-from-an-event-as-parameter/194899/2 "2019-08-12T18:40:54Z")

</div>

Frankly I am amazed you do not get a configuration error on startup. I thought there had to be matching inputs and outputs. pipeline-to-pipeline cannot support this.

---

<div class="post-metadata">

**Author:** ![perryparktung](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@perryparktung](https://discuss.elastic.co/u/perryparktung)\
**Post date:** [August 12, 2019, 7:14pm UTC](https://discuss.elastic.co/t/pipeline-output-filter-not-accepting-existing-fields-from-an-event-as-parameter/194899/3 "2019-08-12T19:14:42Z")

</div>

It took '%{[fields][docType]}' as an actual string and used it. It complained if I hadn't put the double quote in the config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2019, 7:14pm UTC](https://discuss.elastic.co/t/pipeline-output-filter-not-accepting-existing-fields-from-an-event-as-parameter/194899/4 "2019-09-09T19:14:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
