# Pipelines don't working

**URL:** <https://discuss.elastic.co/t/pipelines-dont-working/309793>\
**Category:** Logstash\
**Created:** [July 16, 2022, 1:53pm UTC](https://discuss.elastic.co/t/pipelines-dont-working/309793 "2022-07-16T13:53:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![White\_Hat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/white_hat/32/101868_2.png) [@White\_Hat](https://discuss.elastic.co/u/White_Hat)\
**Post date:** [July 16, 2022, 1:53pm UTC](https://discuss.elastic.co/t/pipelines-dont-working/309793/1 "2022-07-16T13:53:45Z")

</div>

I want to log two separate servers that each has filebeat installed.  
this is my pipeline:

```auto
- pipeline.id: beats-server
  config.string: |
    input { beats { port => 5400 } }
    output {
        if [source] == 'src' {
          pipeline { send_to => src }
        } 
    }

- pipeline.id: src-pr
  path.config: "/etc/logstash/conf.d/pipelines/addr.conf"

```

and this is the config file:

```auto
input {
    pipeline {
        address => src
    }
}

filter {
  json {
    source => "message"
    target => "message"
  }
}

output {
    if [log][file][path] =~ "/var/logs/xxx/" {
      elasticsearch {
    hosts => "127.0.0.1:9200"
    index => "idx"
    user => "xxxx"
    password => "xxxx"
      }
   }
}

```

the service starts successfully but logs cannot shown in kibana.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2022, 4:05pm UTC](https://discuss.elastic.co/t/pipelines-dont-working/309793/2 "2022-07-16T16:05:25Z")

</div>

> [@White\_Hat](#):
>
> ```
> if [source] == 'src' {
> 
> if [log][file][path] =~ "/var/logs/xxx/" {
> 
> ```

What in your filebeat configuration makes you think those conditionals will evaluate to true?

---

<div class="post-metadata">

**Author:** ![White\_Hat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/white_hat/32/101868_2.png) [@White\_Hat](https://discuss.elastic.co/u/White_Hat)\
**Post date:** [July 17, 2022, 6:04am UTC](https://discuss.elastic.co/t/pipelines-dont-working/309793/3 "2022-07-17T06:04:13Z")

</div>

if I run logstash without pipeline everything is good. this is the filebeat configuration:

```auto
filebeat.inputs:

- type: filestream
  fields:
    source: 'src'
  enabled: true
  paths:
    - /var/logs/xxx/*.log

```

---

<div class="post-metadata">

**Author:** ![White\_Hat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/white_hat/32/101868_2.png) [@White\_Hat](https://discuss.elastic.co/u/White_Hat)\
**Post date:** [July 17, 2022, 6:35am UTC](https://discuss.elastic.co/t/pipelines-dont-working/309793/4 "2022-07-17T06:35:30Z")

</div>

finally I solved the problem with adding

```auto
fields_under_root: true

```

in filebeat configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2022, 6:36am UTC](https://discuss.elastic.co/t/pipelines-dont-working/309793/5 "2022-08-14T06:36:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
