# Everchanging Pattern - Logstash

**URL:** <https://discuss.elastic.co/t/everchanging-pattern-logstash/89209>\
**Category:** Logstash\
**Created:** [June 13, 2017, 2:25pm UTC](https://discuss.elastic.co/t/everchanging-pattern-logstash/89209 "2017-06-13T14:25:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![adic26](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@adic26](https://discuss.elastic.co/u/adic26)\
**Post date:** [June 13, 2017, 2:25pm UTC](https://discuss.elastic.co/t/everchanging-pattern-logstash/89209/1 "2017-06-13T14:25:58Z")

</div>

Hello all,

I am completely a newbie on this. I have started to use the ELK on my system, and it is great to grab the known patterns. So far I have gotten my system to grab logfiles via Filebeat to parse the logfiles and ship it to logstash , where logstash grabs the known pattern and bob's my uncle!

However, in my situation I have a unique problem. My application sometimes fails on an unknown situation, where I want to assess and then it becomes a known pattern which I would add to logstash configuration. Is there such a system with ELK that it can grab unknown patterns and lets the system admin know ? Or some sort of visualization system that lets me know that there were logfiles that was shipped to logstash, but logstash was unable to recognize the pattern?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 13, 2017, 2:32pm UTC](https://discuss.elastic.co/t/everchanging-pattern-logstash/89209/2 "2017-06-13T14:32:46Z")

</div>

It's not clear from your question what kind of filters you have, but many Logstash filters add tags when they fail. The grok filter for example adds a `_grokparsefailure` tag when none of the provided expressions match the event. You could search for events with that tag in Kibana or you could set up Elastic Watcher or Elastalert to fire an alert when it sees new such events.

---

<div class="post-metadata">

**Author:** ![adic26](https://avatars.discourse-cdn.com/v4/letter/a/258eb7/32.png) [@adic26](https://discuss.elastic.co/u/adic26)\
**Post date:** [June 13, 2017, 2:35pm UTC](https://discuss.elastic.co/t/everchanging-pattern-logstash/89209/3 "2017-06-13T14:35:29Z")

</div>

Thanks so much! I needed a nudge in the right direction.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2017, 2:35pm UTC](https://discuss.elastic.co/t/everchanging-pattern-logstash/89209/4 "2017-07-11T14:35:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
