# Broken grok after the update to Logstash 7.12

**URL:** <https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863>\
**Category:** Logstash\
**Created:** [April 12, 2021, 10:41am UTC](https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863 "2021-04-12T10:41:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviadhaham](https://avatars.discourse-cdn.com/v4/letter/a/58956e/32.png) [@aviadhaham](https://discuss.elastic.co/u/aviadhaham)\
**Post date:** [April 12, 2021, 10:41am UTC](https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863/1 "2021-04-12T10:41:20Z")

</div>

Hello,

In my company, after upgrading our cluster to the latest version 7.12, we noticed that one of our grok patterns stopped working.

Important things to mention:

- The pipeline is functioning correctly, logs are coming in
- The pattern that is written above this one is working
- We don't see any grokfailure tags
- The same grok works in a grok debugger!

So basically, everything is working as desired, apart from this particular grok.

The pattern is

`/%{DATA:AccountId}/%{DATA:StatsId}/%{GREEDYDATA:Filename}`

An example input would be:

`/4420/1021/vhhx13w31r92z1227d62914z41g2mbd11282o341nu.mp4`

Please let us know what you think, as it seems like we tried everything on our end.

Thank you in advance!

Aviad

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2021, 4:25pm UTC](https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863/2 "2021-04-12T16:25:18Z")

</div>

If grok is not matching but you are not getting a \_grokparsefailure tag then that suggests the source field does not exist.

---

<div class="post-metadata">

**Author:** ![aviadhaham](https://avatars.discourse-cdn.com/v4/letter/a/58956e/32.png) [@aviadhaham](https://discuss.elastic.co/u/aviadhaham)\
**Post date:** [April 14, 2021, 7:55pm UTC](https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863/3 "2021-04-14T19:55:02Z")

</div>

Seems like it indeed doesn't exist, doesn't appear in Kibana, and not in the mapping of the index (no \_source field was found).  
Any advice?  
Can I fix it?  
@Badger

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2021, 3:03pm UTC](https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863/4 "2021-04-15T15:03:51Z")

</div>

If the source field does not exist then clearly you can fix it by creating the field, but we have no way of knowing how you should do that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2021, 3:03pm UTC](https://discuss.elastic.co/t/broken-grok-after-the-update-to-logstash-7-12/269863/5 "2021-05-13T15:03:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
