# Upgrade from 1.5 to 2.0: Pattern not defined

**URL:** <https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312>\
**Category:** Logstash\
**Created:** [November 11, 2015, 10:26am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312 "2015-11-11T10:26:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![LansK](https://avatars.discourse-cdn.com/v4/letter/l/dc4da7/32.png) [@LansK](https://discuss.elastic.co/u/LansK)\
**Post date:** [November 11, 2015, 10:26am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/1 "2015-11-11T10:26:08Z")

</div>

I am upgrading from the 1.5 branch to 2.0. I am getting the following errors on startup:

"Default settings used: Filter workers: 1  
The error reported is:  
pattern %{HOST:thehost} not defined  
"

I think %{HOST} is a default pattern included with logstash, so it is not a case of having a bad patterns directory. No problems with 1.5.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 11, 2015, 10:28am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/2 "2015-11-11T10:28:24Z")

</div>

What's your config look like?

---

<div class="post-metadata">

**Author:** ![ESamir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esamir/32/77283_2.png) [@ESamir](https://discuss.elastic.co/u/ESamir)\
**Post date:** [November 11, 2015, 10:41am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/3 "2015-11-11T10:41:16Z")

</div>

The host configuration option is now hosts in logstash 2.0  
[https://www.elastic.co/guide/en/logstash/current/breaking-changes.html](https://www.elastic.co/guide/en/logstash/current/breaking-changes.html)

---

<div class="post-metadata">

**Author:** ![LansK](https://avatars.discourse-cdn.com/v4/letter/l/dc4da7/32.png) [@LansK](https://discuss.elastic.co/u/LansK)\
**Post date:** [November 11, 2015, 10:53am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/4 "2015-11-11T10:53:11Z")

</div>

The config is fairly large to copy and paste and it isn't giving me a line number. And if I try it with --configtest, it surprisingly passes.

I did remove the entire filter {} section and it worked so it is not happy with something there.

I added this to the beginning of every grok stanza, to be safe, following an issue I found on github:

```
patterns_dir => "/etc/logstash/patterns"

```

I've already updated to change "host" to "hosts" since I saw that in the incompatible changes. That's not the problem here, but thanks for the suggestion.

Might it have anything to do with this? [Grok -\> patterns\_dir not working in logstash 1.5.0](https://discuss.elastic.co/t/grok-patterns-dir-not-working-in-logstash-1-5-0/1428) Do I need to install a plugin to access the patterns included with logstash by default?

Edit: confirmed that %{HOST} is a built-in pattern (or at least grok debugger says it is): [https://grokdebug.herokuapp.com/patterns#](https://grokdebug.herokuapp.com/patterns#) (look under grok-patterns)

Edit2: I am not confident that it is related but the logstash log is filling up with permission denied errors like this one for local files:

```
{:timestamp=>"2015-11-11T06:28:13.624000-0500", :message=>"failed to open /var/log/syslog: Permission denied - /var/log/syslog", :level=>:warn}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 11, 2015, 12:05pm UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/5 "2015-11-11T12:05:08Z")

</div>

If you start Logstash with `--debug` it'll tell you about all pattern files and patterns that it reads. That might give you some clues.

---

<div class="post-metadata">

**Author:** ![LansK](https://avatars.discourse-cdn.com/v4/letter/l/dc4da7/32.png) [@LansK](https://discuss.elastic.co/u/LansK)\
**Post date:** [November 12, 2015, 6:56am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/6 "2015-11-12T06:56:10Z")

</div>

Thanks for the tip.

I used --debug but it was a bit overwhelming and still did not display a line number or greater information for the error. I did manage to find that it was actually loading the default patterns from somewhere in /opt/logstash, making the error that much more strange. Is there anyway to force a line number for this error? It doesn't seem like a normal error, especially since I have encountered grok errors before and they are pretty self-explanatory to debug.

---

<div class="post-metadata">

**Author:** ![Jaykah](https://avatars.discourse-cdn.com/v4/letter/j/65b543/32.png) [@Jaykah](https://discuss.elastic.co/u/Jaykah)\
**Post date:** [November 23, 2015, 3:40am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/7 "2015-11-23T03:40:04Z")

</div>

Were you able to figure it out? I am having the same issue.

---

<div class="post-metadata">

**Author:** ![maxwalk](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@maxwalk](https://discuss.elastic.co/u/maxwalk)\
**Post date:** [July 29, 2016, 6:22pm UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/8 "2016-07-29T18:22:39Z")

</div>

%{HOST:domain} =\> %{IPORHOST:domain} fix my problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:45am UTC](https://discuss.elastic.co/t/upgrade-from-1-5-to-2-0-pattern-not-defined/34312/9 "2017-07-06T04:45:53Z")

</div>


