# Grok -\> patterns\_dir not working in logstash 1.5.0

**URL:** <https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428>\
**Category:** Logstash\
**Created:** [May 27, 2015, 11:14pm UTC](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428 "2015-05-27T23:14:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anoban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anoban/32/3466_2.png) [@anoban](https://discuss.elastic.co/u/anoban)\
**Post date:** [May 27, 2015, 11:14pm UTC](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428/1 "2015-05-27T23:14:25Z")

</div>

... in the same way as it did in 1.4.2

I had a complex directory structure in 1.4.2, as I noticed grok would aggregate the patterns in alphabetical order.

This gave me the ability to build a directory structure like:

grok {  
patterns\_dir =\> [  
"/home/elk/ELK/logstash-1.4.2/patterns",  
"/home/elk/ELK/logstash-1.4.2/config/patterns",  
"/home/elk/ELK/logstash-1.4.2/proc",  
"/home/elk/ELK/logstash-1.4.2/services"  
]  
[...]  
}

A pattern could be defined in many places, and the one found in the last folder, services, would be the one used.

However by keeping the config identical and shifting the binaries to point to 1.5.0, I get the following error:  
The error reported is:  
pattern %{MYTEST} not defined

I removed the whole directory structure, aggregated all the pattern files into 1, which I dropped into /home/elk/ELK/logstash-1.5.0/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-0.1.10/patterns/grok-my-patterns

and now it works.

Anyone else noticed the change of behavior?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 27, 2015, 11:47pm UTC](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428/2 "2015-05-27T23:47:54Z")

</div>

Yes. The behavior has changed. Since [logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core) is now a ruby gem, it will not work the same way with the patterns\_dir as before. As a result, you shouldn't need to add the original patterns via a patterns\_dir directive. Only new pattern directories should need to be added, as the existing patterns will always be read first.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2015, 6:35am UTC](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428/4 "2015-08-24T06:35:54Z")

</div>

Specify an absolute path as the pattern directory. Relative paths appear to be allowed here but I wouldn't recommend it.

---

<div class="post-metadata">

**Author:** ![Hoan\_Hp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoan_hp/32/13861_2.png) [@Hoan\_Hp](https://discuss.elastic.co/u/Hoan_Hp)\
**Post date:** [December 14, 2016, 4:08am UTC](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428/6 "2016-12-14T04:08:18Z")

</div>

please tell me how can you get the specify error like that? When i did somthing wrong in config file, it always show a mess ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:29am UTC](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428/7 "2017-07-06T04:29:52Z")

</div>


