Skip to content

[ES|QL] Fixes not recognized GROK patterns#246871

Merged
momovdg merged 1 commit intoelastic:mainfrom
momovdg:esql-grok-patterns-not-recognized
Dec 19, 2025
Merged

[ES|QL] Fixes not recognized GROK patterns#246871
momovdg merged 1 commit intoelastic:mainfrom
momovdg:esql-grok-patterns-not-recognized

Conversation

@momovdg
Copy link
Contributor

@momovdg momovdg commented Dec 18, 2025

resolves #246803

Summary

Some patterns in the GROK command were not properly recognized and were producing unknown columns in the query.

before
image

after
image

Checklist

Check the PR satisfies following conditions.

Reviewers should verify this PR satisfies this list as well.

  • Unit or functional tests were updated or added to match the most common scenarios
  • The PR description includes the appropriate Release Notes section, and the correct release_note:* label is applied per the guidelines
  • Review the backport guidelines and apply applicable backport:* labels.
@momovdg momovdg self-assigned this Dec 18, 2025
@momovdg momovdg added release_note:skip Skip the PR/issue when compiling release notes Feature:ES|QL ES|QL related features in Kibana Team:ESQL ES|QL related features in Kibana t// backport:version Backport to applied version labels v9.3.0 v9.4.0 labels Dec 18, 2025
@momovdg momovdg force-pushed the esql-grok-patterns-not-recognized branch from 53ecc9f to b42170f Compare December 18, 2025 15:09
@elasticmachine
Copy link
Contributor

elasticmachine commented Dec 18, 2025

💛 Build succeeded, but was flaky

Failed CI Steps

Test Failures

  • [job] [logs] FTR Configs #19 / discover/tabs discover - ES|QL controls should add an ES|QL multi - value control
  • [job] [logs] FTR Configs #19 / discover/tabs discover - ES|QL controls should add an ES|QL value control

Metrics [docs]

Page load bundle

Size of the bundles that are downloaded on every page load. Target size is below 100kb

id before after diff
kbnUiSharedDeps-srcJs 4.3MB 4.3MB +7.0B

History

cc @momovdg

@momovdg momovdg marked this pull request as ready for review December 18, 2025 18:19
@momovdg momovdg requested a review from a team as a code owner December 18, 2025 18:19
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-esql (Team:ESQL)

@stratoula stratoula added release_note:fix and removed release_note:skip Skip the PR/issue when compiling release notes labels Dec 19, 2025
@stratoula stratoula changed the title [ES|QL] GROK patterns not recognized Dec 19, 2025
Copy link
Contributor

@stratoula stratoula left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

I changed the label to fix (this means that our release notes will mention it as a bug fix)

@momovdg momovdg merged commit 24f3c3d into elastic:main Dec 19, 2025
20 checks passed
@kibanamachine
Copy link
Contributor

Starting backport for target branches: 9.3

https://github.com/elastic/kibana/actions/runs/20363342144

kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Dec 19, 2025
resolves elastic#246803

## Summary

Some patterns in the GROK command were not properly recognized and were
producing unknown columns in the query.

before
<img width="743" height="815" alt="image"
src="https://github.com/user-attachments/assets/417c16c3-cd61-40e4-bf43-aa3695e52e3d"
/>

after
<img width="766" height="795" alt="image"
src="https://github.com/user-attachments/assets/8323fcd2-d6a7-41f8-90cf-7eb7176639d1"
/>

### Checklist

Check the PR satisfies following conditions.

Reviewers should verify this PR satisfies this list as well.

- [x] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios
- [x] The PR description includes the appropriate Release Notes section,
and the correct `release_note:*` label is applied per the
[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- [x] Review the [backport
guidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)
and apply applicable `backport:*` labels.

(cherry picked from commit 24f3c3d)
@kibanamachine
Copy link
Contributor

💚 All backports created successfully

Status Branch Result
9.3

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request Dec 19, 2025
# Backport

This will backport the following commits from `main` to `9.3`:
- [[ES|QL] Fixes not recognized GROK patterns
(#246871)](#246871)

<!--- Backport version: 9.6.6 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Panagiotis Van de
Goor","email":"44780623+momovdg@users.noreply.github.com"},"sourceCommit":{"committedDate":"2025-12-19T07:41:35Z","message":"[ES|QL]
Fixes not recognized GROK patterns (#246871)\n\nresolves
https://github.com/elastic/kibana/issues/246803\n\n## Summary\n\nSome
patterns in the GROK command were not properly recognized and
were\nproducing unknown columns in the query.\n\nbefore\n<img
width=\"743\" height=\"815\"
alt=\"image\"\nsrc=\"https://github.com/user-attachments/assets/417c16c3-cd61-40e4-bf43-aa3695e52e3d\"\n/>\n\nafter\n<img
width=\"766\" height=\"795\"
alt=\"image\"\nsrc=\"https://github.com/user-attachments/assets/8323fcd2-d6a7-41f8-90cf-7eb7176639d1\"\n/>\n\n\n###
Checklist\n\nCheck the PR satisfies following conditions. \n\nReviewers
should verify this PR satisfies this list as well.\n\n- [x] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"24f3c3d630a84ccb59c1b3a3f22d18b3f7dfebb6","branchLabelMapping":{"^v9.4.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Feature:ES|QL","Team:ESQL","backport:version","v9.3.0","v9.4.0"],"title":"[ES|QL]
Fixes not recognized GROK
patterns","number":246871,"url":"https://github.com/elastic/kibana/pull/246871","mergeCommit":{"message":"[ES|QL]
Fixes not recognized GROK patterns (#246871)\n\nresolves
https://github.com/elastic/kibana/issues/246803\n\n## Summary\n\nSome
patterns in the GROK command were not properly recognized and
were\nproducing unknown columns in the query.\n\nbefore\n<img
width=\"743\" height=\"815\"
alt=\"image\"\nsrc=\"https://github.com/user-attachments/assets/417c16c3-cd61-40e4-bf43-aa3695e52e3d\"\n/>\n\nafter\n<img
width=\"766\" height=\"795\"
alt=\"image\"\nsrc=\"https://github.com/user-attachments/assets/8323fcd2-d6a7-41f8-90cf-7eb7176639d1\"\n/>\n\n\n###
Checklist\n\nCheck the PR satisfies following conditions. \n\nReviewers
should verify this PR satisfies this list as well.\n\n- [x] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"24f3c3d630a84ccb59c1b3a3f22d18b3f7dfebb6"}},"sourceBranch":"main","suggestedTargetBranches":["9.3"],"targetPullRequestStates":[{"branch":"9.3","label":"v9.3.0","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"main","label":"v9.4.0","branchLabelMappingKey":"^v9.4.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/246871","number":246871,"mergeCommit":{"message":"[ES|QL]
Fixes not recognized GROK patterns (#246871)\n\nresolves
https://github.com/elastic/kibana/issues/246803\n\n## Summary\n\nSome
patterns in the GROK command were not properly recognized and
were\nproducing unknown columns in the query.\n\nbefore\n<img
width=\"743\" height=\"815\"
alt=\"image\"\nsrc=\"https://github.com/user-attachments/assets/417c16c3-cd61-40e4-bf43-aa3695e52e3d\"\n/>\n\nafter\n<img
width=\"766\" height=\"795\"
alt=\"image\"\nsrc=\"https://github.com/user-attachments/assets/8323fcd2-d6a7-41f8-90cf-7eb7176639d1\"\n/>\n\n\n###
Checklist\n\nCheck the PR satisfies following conditions. \n\nReviewers
should verify this PR satisfies this list as well.\n\n- [x] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [x] The PR
description includes the appropriate Release Notes section,\nand the
correct `release_note:*` label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[x] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*`
labels.","sha":"24f3c3d630a84ccb59c1b3a3f22d18b3f7dfebb6"}}]}]
BACKPORT-->

Co-authored-by: Panagiotis Van de Goor <44780623+momovdg@users.noreply.github.com>
@momovdg momovdg deleted the esql-grok-patterns-not-recognized branch December 19, 2025 12:48
CAWilson94 pushed a commit to CAWilson94/kibana that referenced this pull request Jan 6, 2026
resolves elastic#246803

## Summary

Some patterns in the GROK command were not properly recognized and were
producing unknown columns in the query.

before
<img width="743" height="815" alt="image"
src="https://github.com/user-attachments/assets/417c16c3-cd61-40e4-bf43-aa3695e52e3d"
/>

after
<img width="766" height="795" alt="image"
src="https://github.com/user-attachments/assets/8323fcd2-d6a7-41f8-90cf-7eb7176639d1"
/>


### Checklist

Check the PR satisfies following conditions. 

Reviewers should verify this PR satisfies this list as well.

- [x] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios
- [x] The PR description includes the appropriate Release Notes section,
and the correct `release_note:*` label is applied per the
[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- [x] Review the [backport
guidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)
and apply applicable `backport:*` labels.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:version Backport to applied version labels Feature:ES|QL ES|QL related features in Kibana release_note:fix Team:ESQL ES|QL related features in Kibana t// v9.3.0 v9.4.0

4 participants