# Pipeline-to-pipeline with single input and output

**URL:** <https://discuss.elastic.co/t/pipeline-to-pipeline-with-single-input-and-output/223631>\
**Category:** Logstash\
**Created:** [March 14, 2020, 6:45pm UTC](https://discuss.elastic.co/t/pipeline-to-pipeline-with-single-input-and-output/223631 "2020-03-14T18:45:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Burga](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@Burga](https://discuss.elastic.co/u/Burga)\
**Post date:** [March 14, 2020, 6:45pm UTC](https://discuss.elastic.co/t/pipeline-to-pipeline-with-single-input-and-output/223631/1 "2020-03-14T18:45:25Z")

</div>

Hi , I'm trying to configure logstash with pipelines configuration

logstash pipelines:

input --\> conf files with different log types (system,security, auditing ...) --\> output

but it doesn't work(without errors ) , what I'm doing wrong

beats\_input.conf(input):

input {  
beats {  
port =\> 5044  
client\_inactivity\_timeout =\> 600  
}  
}

output {  
if [fileset][module] == "system" {  
if [fileset][name] == "auth" {  
pipeline { send\_to =\> system\_auth }  
}  
if [fileset][name] == "syslog" {  
pipeline {send\_to =\> system\_syslog }  
}  
}  
}

system.conf:

input {

pipeline {address =\> system\_syslog}

}

filter {

```
  grok {
     add_field => { "[@metadata][index]" => "system-syslog" }

    match => { "message" => ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:\[%{POSINT:[system][syslog][pid]}\])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }
    pattern_definitions => { "GREEDYMULTILINE" => "(.|\n)*" }
    remove_field => "message"
  }
  date {
    match => ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
  }
}

```

output {  
pipeline{send\_to=\>elasticsearch}

}

elasticsearch(output):

input {  
pipeline{address =\> elasticsearch}

}

output {  
elasticsearch {  
hosts =\> ["il-infra-es1", "il-infra-es2", "il-infra-es3"]  
manage\_template =\> false  
index =\> "%{[@metadata][index]}-%{+YYYY.MM.dd}"  
}  
}

pipelines.yml:

- pipeline.id: beats\_input  
path.config: "/etc/logstash/conf.d/beats\_input.conf"
- pipeline.id: system-auth  
path.config: "/etc/logstash/conf.d/system\_auth.conf"
- pipeline.id: system-syslog  
path.config: "/etc/logstash/conf.d/system\_syslog.conf"
- pipeline.id: elasticsearch  
path.config: "/etc/logstash/conf.d/elasticsearch.conf"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2020, 6:45pm UTC](https://discuss.elastic.co/t/pipeline-to-pipeline-with-single-input-and-output/223631/2 "2020-04-11T18:45:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
