# Reroute logs in different dataset/datastreams/data\_namespaces

**URL:** <https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282>\
**Category:** Logs\
**Created:** [May 11, 2026, 1:46pm UTC](https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282 "2026-05-11T13:46:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![proclick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/proclick/32/139736_2.png) [@proclick](https://discuss.elastic.co/u/proclick)\
**Post date:** [May 11, 2026, 1:46pm UTC](https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282/1 "2026-05-11T13:46:45Z")

</div>

Hello guys,

I ingest logs from one SaaS solution though the pre-built elastic agent integration. The logs are pretty noisy and I want to reroute them in different namespaces (data streams) to apply different ILM policies.  
What are my options?  
I have tried to reroute those logs via \*@custom pipeline using different fields and it has broken the integration (at least there were no logs from the integration before I made the pipeline empty (deleted all processors) lol). I am thinking of adding the reroute processors in the "final pipeline" after the logs are parsed. Is it a good idea at all?

I would appreciate any help regarding this.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 11, 2026, 2:45pm UTC](https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282/2 "2026-05-11T14:45:12Z")

</div>

> [@proclick](#):
>
> I have tried to reroute those logs via \*@custom pipeline using different fields and it has broken the integration (at least there were no logs from the integration before I made the pipeline empty (deleted all processors) lol).

How exactly you reroute them and what broke? Can you provide more context.

> [@proclick](#):
>
> I am thinking of adding the reroute processors in the "final pipeline" after the logs are parsed. Is it a good idea at all?

The last pipeline you have access to make changes is the `@custom` one for each integration, so any reroute processor needs to be in this pipeline.

A common issue when using the `reroute` are related to permissions, per default each integration will only have permission to write on the data streams and namespace configured on the policy, since 9.1+ you have an option to add extra permissions to use the `reroute` processor.

In which version are you and what are the integrations that you want to reroute?

---

<div class="post-metadata">

**Author:** ![proclick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/proclick/32/139736_2.png) [@proclick](https://discuss.elastic.co/u/proclick)\
**Post date:** [May 11, 2026, 3:08pm UTC](https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282/3 "2026-05-11T15:08:34Z")

</div>

Thank you for your reply!

So the logs were rerouting in @customcustom pipeline and everything was working fine. The reroute was made by the field

```auto
[

  {

    "set": {

      "description": "Ensure message field exists before managed pipeline rename processor",

      "override": false,

      "field": "message",

      "copy_from": "event.original",

      "if": "ctx.message == null && ctx?.event?.original != null"

    }

  },

  {

    "reroute": {

      "namespace": "traffic_allow",

      "if": "ctx?.panw?.panos?.type != null && ctx.panw.panos.type.toString().equalsIgnoreCase('TRAFFIC') && ctx?.panw?.panos?.action != null && ctx.panw.panos.action.toString().equalsIgnoreCase('allow') && ctx?.data_stream?.namespace != 'traffic_allow'"

    }

  },

  {

    "reroute": {

      "namespace": "traffic_deny",

      "if": "ctx?.panw?.panos?.type != null && ctx.panw.panos.type.toString().equalsIgnoreCase('TRAFFIC') && ctx?.panw?.panos?.action != null && ctx.panw.panos.action.toString().equalsIgnoreCase('deny') && ctx?.data_stream?.namespace != 'traffic_deny'"

    }

  },

  {

    "reroute": {

      "namespace": "traffic",

      "if": "ctx?.panw?.panos?.type != null && ctx.panw.panos.type.toString().equalsIgnoreCase('TRAFFIC') && ctx?.data_stream?.namespace != 'traffic'"

    }

  },

  {

```

Everything was working fine, after we restarted integration server, logs just stopped delivering at some point. New data systems (per namespace) were successfully created. It just stopped for whatever reason. When I cleaned up the custom pipeline, logs continued delivering to the default index. So the issue is not the permissions, I guess. There were no errors in the logs (or I just missed) and no errors from in the elastic agent integration.

Palo Alto NGFW integration  
Version 9.3
