# Question: define default pipeline with different patterns depending on log.file.path

**URL:** <https://discuss.elastic.co/t/question-define-default-pipeline-with-different-patterns-depending-on-log-file-path/268636>\
**Category:** Elasticsearch\
**Created:** [March 29, 2021, 8:59am UTC](https://discuss.elastic.co/t/question-define-default-pipeline-with-different-patterns-depending-on-log-file-path/268636 "2021-03-29T08:59:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christos\_Gitsis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_gitsis/32/56529_2.png) [@Christos\_Gitsis](https://discuss.elastic.co/u/Christos_Gitsis)\
**Post date:** [March 29, 2021, 8:59am UTC](https://discuss.elastic.co/t/question-define-default-pipeline-with-different-patterns-depending-on-log-file-path/268636/1 "2021-03-29T08:59:58Z")

</div>

Hi,

I would like to have my logs ingested by two different pipelines, depending on the log file which is the source of the document.

- Everything coming from /var/log/a.log should be processed by a\_pipeline
- everything from /var/log/b.log by b\_pipeline
- for everything else I would like to have the document unaltered (no ingest pipeline)

I am trying something like:

```
PUT _ingest/pipeline/log_pipeline
{
   "description":"A pipeline of pipelines for log files",
   "processors":[
      {
         "pipeline":{
            "if":"log.file.path == '/var/log/a.log'",
            "name":"a_pipeline"
         }
      },
      {
         "pipeline":{
            "if":"log.file.path == '/var/log/b.log'",
            "name":"b_pipeline"
         }
      }
   ]
}

```

My a and b pipelines look something like this and seem to work as intended during simulation.

```
PUT /_ingest/pipeline/a_pipeline
{
    "description" : "A pipeline",
    "processors" : [
      {
        "grok" : {
          "field" : "message",
          "ignore_missing": true, 
          "patterns" : ["%{TIMESTAMP_ISO8601:tstamp};%{GREEDYDATA:payload}"]
        }
      }
    ]
}

```

However when add log\_pipeline as a default\_pipeline to my index, I don't find any messages at all in my index. Is my syntax with "if":"log.file.path == '/var/log/a.log'" wrong? what would be the correct syntax in order to delegate to different pipelines depending on the log file?

---

<div class="post-metadata">

**Author:** ![Christos\_Gitsis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_gitsis/32/56529_2.png) [@Christos\_Gitsis](https://discuss.elastic.co/u/Christos_Gitsis)\
**Post date:** [March 29, 2021, 10:25am UTC](https://discuss.elastic.co/t/question-define-default-pipeline-with-different-patterns-depending-on-log-file-path/268636/2 "2021-03-29T10:25:51Z")

</div>

I think I found it myself, I had to replace log.file.path with ctx.log.file.path

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 29, 2021, 3:13pm UTC](https://discuss.elastic.co/t/question-define-default-pipeline-with-different-patterns-depending-on-log-file-path/268636/3 "2021-03-29T15:13:53Z")

</div>

Hi @Christos_Gitsis

Good News can you post your solutions so others can see?

Yup have to use the` ctx.` in the conditionals

Also this is a great pattern.

I always create a top-level pipeline that can then conditionally call sub-pipelines, and if you build modular you can also use in other pipelines... its almost like its code 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2021, 3:14pm UTC](https://discuss.elastic.co/t/question-define-default-pipeline-with-different-patterns-depending-on-log-file-path/268636/4 "2021-04-26T15:14:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
