# Upgrade to LS 1.5.5 breaks my config

**URL:** <https://discuss.elastic.co/t/upgrade-to-ls-1-5-5-breaks-my-config/34633>\
**Category:** Logstash\
**Created:** [November 16, 2015, 2:28am UTC](https://discuss.elastic.co/t/upgrade-to-ls-1-5-5-breaks-my-config/34633 "2015-11-16T02:28:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [November 16, 2015, 2:28am UTC](https://discuss.elastic.co/t/upgrade-to-ls-1-5-5-breaks-my-config/34633/1 "2015-11-16T02:28:20Z")

</div>

Hey all,

I had a config that was working just fine under Logstash 1.5.4. But I just upgraded to version 1.5.5, and now LS won't run correctly. No data is showing up in Kibana, where before the upgrade data was showing up fine.

And I now see this error showing up in the logstash.log:

```
{:timestamp=>"2015-11-15T21:22:13.276000-0500", :message=>"The error reported is: \n pattern %{HOST:jf_host} not defined"}
{:timestamp=>"2015-11-15T21:23:42.256000-0500", :message=>"The error reported is: \n pattern %{HOST:jf_host} not defined"}

```

That's a new error since the upgrade!

This is the field in my config that LS is now complaining about:

```
%{HOST:jf_host}

```

Here's what the entire grok filter looks like:

```
 grok {
            match => { 'message' => '%{SYSLOGTIMESTAMP:syslog_timestamp} %{HOST:jf_host} %{SYSLOGPROG:appname_pid}: %{GREEDYDATA:log_message}'}
        }

```

So why would this setup be fine under 1.5.4, but not version 1.5.5? And how can I fix this so I get my setup working again?

---

<div class="post-metadata">

**Author:** ![ceekay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ceekay/32/5687_2.png) [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Post date:** [November 16, 2015, 2:37am UTC](https://discuss.elastic.co/t/upgrade-to-ls-1-5-5-breaks-my-config/34633/2 "2015-11-16T02:37:33Z")

</div>

HOST used to be an alias for HOSTNAME, and under 2.0 at least, this has been removed. It looks like the same issue for 1.5.5, from what you're describing.

Try `%{HOSTNAME:jf_host}` instead.

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [November 16, 2015, 2:45am UTC](https://discuss.elastic.co/t/upgrade-to-ls-1-5-5-breaks-my-config/34633/3 "2015-11-16T02:45:02Z")

</div>

> [@ceekay](#):
>
> HOST used to be an alias for HOSTNAME, and under 2.0 at least, this has been removed. It looks like the same issue for 1.5.5, from what you're describing.
> 
> Try `%{HOSTNAME:jf_host}` instead.

Yup! That was it. Love the responsiveness of this board! Works now.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:22am UTC](https://discuss.elastic.co/t/upgrade-to-ls-1-5-5-breaks-my-config/34633/4 "2017-07-06T05:22:45Z")

</div>


