Skip to content
CAI
Software that uses CAICheck a score

logstash-plugins/logstash-patterns-core

62.2

Adequate · 19 September 2026

17

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the core pattern library for the Logstash Grok filter, providing reusable regular expression definitions for parsing diverse log sources. It maintains a dual structure of legacy patterns for backward compatibility and a comprehensive set of ECS-compliant patterns that standardize field names across various services like AWS, firewalls, and databases. The repository focuses on defining these parsing rules and validating their correctness through a dedicated test suite, rather than implementing the filtering logic itself.

Features

Initial release of logstash-patterns-core version 4.3.4

This entry marks the initial commit of the repository, establishing the baseline for the logstash-patterns-core plugin at version 4.3.4. The release includes the core pattern definitions compliant with the Elastic Common Schema (ECS), a comprehensive CHANGELOG documenting fixes for patterns like CISCOFW, CLOUDFRONT\_ACCESS\_LOG, and BIN9\_QUERYLOG, and standard project infrastructure files such as the Apache 2.0 LICENSE, NOTICE, and CONTRIBUTORS list. It also updates the CI badge to GitHub Actions and adds a Rakefile requirement for logstash devutils.

(repo-wide) · high confidence

New ECS v1 log parsing patterns for AWS, Bacula, BIND, Bro, Exim, Firewalls, HAProxy, HTTPD, Java, Junos, Linux Syslog, Maven, Mcollective, MongoDB, and Nagios

This release introduces a comprehensive set of new Grok patterns under the \patterns/ecs-v1\ directory, enabling structured parsing of logs from a wide variety of sources into the Elastic Common Schema (ECS) v1 format. The new patterns cover AWS services (S3, ELB, CloudFront), backup software (Bacula), DNS servers (BIND), network security tools (Bro/Zeek, Cisco ASA, Juniper SRX, NetScreen, iptables, Shorewall, SuSE Firewall 2), mail servers (Exim), load balancers (HAProxy), web servers (Apache/HTTPD), application logs (Java/Tomcat), system utilities (Linux Syslog, Cron, PAM), build tools (Maven), distributed computing (Mcollective), databases (MongoDB), and monitoring systems (Nagios). Users can now ingest and correlate these diverse log types with consistent field names.

patterns/ecs-v1 · high confidence

Removals

Removal of Java and Junos pattern definitions

The Java and Junos pattern files have been deleted from the repository. This removes the previously defined patterns for Java class names, file names, methods (including special methods like \<init\> and \<clinit\>), and stack trace parts, as well as the Junos RT\_FLOW session creation, closure, and denial patterns. Users relying on these specific pattern definitions for parsing Java logs or Junos flow logs will no longer have these patterns available.

patterns · high confidence

Removal of gem publishing and vendor file management rake tasks

The \rakelib/publish.rake\ and \rakelib/vendor.rake\ files have been deleted, removing the \publish\_gem\ task used to publish gems to RubyGems.org and the \vendor\ task along with its associated helper methods for downloading and extracting third-party dependencies. Users can no longer use these Rake tasks to manage gem releases or vendor external libraries within the project.

rakelib · high confidence

Behavioural changes

Legacy log parsing patterns reorganized and expanded

Log parsing patterns for AWS, Bacula, BIND, Bro, Exim, HTTPD, Java, Junos, Maven, Rails, Squid, and various firewalls (Cisco ASA, Shorewall, SuSE) have been moved into a new \patterns/legacy\ directory. The core \grok-patterns\ file has been updated to support broader character sets in email addresses, URIs, and months, while removing duplicate Apache log definitions now handled in the HTTPD file. Additionally, new patterns have been added for MongoDB 3.x logs, Nagios notification controls, Redis monitoring logs, and Syslog 5424 base formats, enhancing the ability to parse these specific log sources.

patterns/legacy · high confidence

Logstash patterns now support ECS-compliant capture paths

The core patterns module has been refactored to support multiple pattern sets, specifically introducing an 'ecs-v1' path alongside the existing 'legacy' path. Users can now access ECS-compliant pattern definitions via the new path configuration, while the legacy patterns remain available for backward compatibility. This change enables Logstash to align with Elastic Common Schema standards for log parsing.

lib/logstash · high confidence

Test coverage

Added test coverage for AWS, Bacula, BIND, Bro/Zeek, Exim, and Firewall log patterns; Added test infrastructure for Grok filter validation.

Dependencies

Updated gemspec for Logstash 2.0 plugin API and modernized build configuration

The gemspec has been updated to depend on the new logstash-core-plugin-api (versions 1.60 to 2.99) instead of the legacy logstash gem, aligning with the Logstash 2.0 plugin architecture. The project also switched to using a version file for dynamic versioning, replaced git ls-files with explicit directory globs for file listing, and added development dependencies for logstash-devutils and logstash-filter-grok to support testing and local development workflows.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 62.

Lenses

  • Code Health 98
  • Architecture 69
  • Maturity 55
  • Readiness 62
  • Security 74

Changes since last survey

  • 185 commits — 159 feature/other, 26 fixes

By area

  • (root) — 81 commits
  • spec/patterns — 32 commits
  • patterns/grok-patterns — 24 commits
  • patterns/firewalls — 9 commits
  • (repo) — 4 commits
  • patterns/java — 4 commits
  • patterns/linux-syslog — 4 commits
  • patterns/aws — 3 commits
  • patterns/haproxy — 3 commits
  • patterns/nagios — 3 commits
  • patterns/s3 — 3 commits
  • patterns/exim — 2 commits
  • spec/spec_helper.rb — 2 commits
  • patterns/bacula — 1 commit
  • patterns/bind — 1 commit
  • patterns/bro — 1 commit
  • patterns/ecs-v1 — 1 commit
  • patterns/httpd — 1 commit
  • patterns/junos — 1 commit
  • patterns/legacy — 1 commit

Notable commits

  • fix: Added regression test to make sure that TIMEPERIOD TRANSITION doesn't end with a semi-colon (;)
  • fix: Build: revert the need to use a git source (#302)
  • fix: Chore: Fix broken link on readme. (#305)
  • fix: Fix #93, add test that checks for matched values
  • fix: Fix error with commit
  • fix: Fix error with commit
  • fix: Fix grokparsefailure due to truncated http_request.
  • fix: Fix: HTTPD access log parse failure on missing response (#282)
  • fix: Fix: Java stack trace's JAVAFILE to better match generated names (#272)
  • fix: Fix: NAGIOS TIMEPERIOD unknown (from/to) field matching (#275)
  • fix: Fix: UNIXPATH to avoid DoS on long paths with unmatching chars (#292)
  • fix: Fix: Use greedy matching for UNIXPATH pattern
  • fix: Fix: incorrect syslog (priority) field name (#303)
  • fix: Fix: match Information/INFORMATION in LOGLEVEL (#274)
  • fix: Fix: parsing x-edge-location in CLOUDFRONT_ACCESS_LOG (#311)
  • fix: Fixed nagios timetransition pattern
  • fix: Test: fix and add ECS compatibility specs (#310)
  • fix: Version 0.1.10 bump, including a fix for the logstash_home issue
  • fix: fix CISCOFW302013_302014_302015_302016 grok pattern (#313)
  • fix: fix COMMONAPACHELOG specs
  • …and 165 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

logstash-plugins/logstash-patterns-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 74a4098582d3331a2b9b18c04d2446f2c0efb648 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.