# AWS RDS Postgres Provided Grok expressions do not match field value

**URL:** <https://discuss.elastic.co/t/aws-rds-postgres-provided-grok-expressions-do-not-match-field-value/129116>\
**Category:** Elasticsearch\
**Created:** [April 23, 2018, 1:25pm UTC](https://discuss.elastic.co/t/aws-rds-postgres-provided-grok-expressions-do-not-match-field-value/129116 "2018-04-23T13:25:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![toontilley](https://avatars.discourse-cdn.com/v4/letter/t/c2a13f/32.png) [@toontilley](https://discuss.elastic.co/u/toontilley)\
**Post date:** [April 23, 2018, 1:25pm UTC](https://discuss.elastic.co/t/aws-rds-postgres-provided-grok-expressions-do-not-match-field-value/129116/1 "2018-04-23T13:25:43Z")

</div>

I'm trying to setup Filebeat with the postgres module to publish logs from an AWS/RDS instance to elasticsearch. I have a python script which can download the logs and the output looks like this:

```
2018-04-18 08:10:50 UTC:111.222.333.444(54888):root@postgres:[11162]:LOG: statement: SELECT

```

Filebeat is able to publish the data to elasticsearch and when I view it in Kibana I see the following error:

```
 "error": {
  "message": "Provided Grok expressions do not match field value:

```

Trying to diagnose the problem my self and I was able to publish a normal postgres log from another server which wasnt and RDS instance.

The output for that log was:  
2018-04-19 08:11:37.248 UTC [4369] mhowland@postgres ERROR: permission denied for schema pgagent

I noticed the output were different and had different fields so I created a GROK filter and found this works:

```
%{DATESTAMP:timestamp} %{TZ}:%{IP:ip_address}%{DATA:thread_id}:%{DATA:user}@%{DATA:database}:%{DATA:connection_id}:%{DATA:level}: %{GREEDYDATA:message}

```

But this is where I am stuck on what to do next with this filter. It would be good to know if I am doing this correctly should I be using logstash? The documentation for the postgresql modules says I should be publishing the data straight to elasticsearch.

First post on here so apologies in advance if I have posted this incorrectly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2018, 1:25pm UTC](https://discuss.elastic.co/t/aws-rds-postgres-provided-grok-expressions-do-not-match-field-value/129116/2 "2018-05-21T13:25:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
