# Logstash: Grok patterns location

**URL:** <https://discuss.elastic.co/t/logstash-grok-patterns-location/231295>\
**Category:** Logstash\
**Created:** [May 6, 2020, 8:50am UTC](https://discuss.elastic.co/t/logstash-grok-patterns-location/231295 "2020-05-06T08:50:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [May 6, 2020, 8:50am UTC](https://discuss.elastic.co/t/logstash-grok-patterns-location/231295/1 "2020-05-06T08:50:55Z")

</div>

As given by [example](https://qbox.io/blog/logstash-grok-filter-tutorial-patterns)

```auto
# contents of ./patterns/postfix:
POSTFIX_QUEUEID [0-9A-F]{10,11}

```

Raw data

```auto
Jan 1 06:25:43 mailserver14 postfix/cleanup[21403]: BEF25A72965: message-id=<20130101142543.5828399CCAF@mailserver14.example.com>

```

The corresponding Grok filter configuration will be:

```auto
filter {
 grok {
 patterns_dir => ["./patterns"]
 match => { "message" => "%{SYSLOGBASE} %{POSTFIX_QUEUEID:queue_id}: %{GREEDYDATA:syslog_message}" }
 }
}

```

Just to understand few bits

1. Can the `patterns_dir` be specified "relative" to the installation directory of logstash? (eg something like `$LOGSTASH_HOME/mypatterns/` )
2. if NOT, can we specify the patterns directory in absolute terms to OS? (eg something like `/tmp/logstash/configs/patterns`) ?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 6, 2020, 10:49am UTC](https://discuss.elastic.co/t/logstash-grok-patterns-location/231295/2 "2020-05-06T10:49:07Z")

</div>

1. yes you can. you can also define environment variable as specified in [https://www.elastic.co/guide/en/logstash/current/environment-variables.html](https://www.elastic.co/guide/en/logstash/current/environment-variables.html)

2. absolute path always works . just remember that user who runs logstash needs to have sufficient permission to the paths

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [May 6, 2020, 11:05am UTC](https://discuss.elastic.co/t/logstash-grok-patterns-location/231295/3 "2020-05-06T11:05:27Z")

</div>

thanks mate.  
Just on the "export" of environment variable (couldn't be clear from the document). Where should that export happen? When you start logstash (command line on the shell?) or is there are variable file where we fill up and put as a config file?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 6, 2020, 11:36am UTC](https://discuss.elastic.co/t/logstash-grok-patterns-location/231295/4 "2020-05-06T11:36:24Z")

</div>

if you’re using systemd to run logstash, you can add your vars to /etc/default/logstash. if you run logstash from CLI, you can add them to /etc/environment or to your shell’s profile (.bash\_profile or equivalent). you can check if vars are lodes by running env command. implementation varies between OS and distribution, so best to check your system’s docs on how to set systemwide variables

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2020, 11:36am UTC](https://discuss.elastic.co/t/logstash-grok-patterns-location/231295/5 "2020-06-03T11:36:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
