# Dont have Query count and cumulated duration \[Filebeat PostgreSQL\]

**URL:** <https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 25, 2019, 4:43pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799 "2019-03-25T16:43:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![patsevanton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patsevanton/32/42692_2.png) [@patsevanton](https://discuss.elastic.co/u/patsevanton)\
**Post date:** [March 25, 2019, 4:43pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799/1 "2019-03-25T16:43:12Z")

</div>

Hi. ELK stack version 6.6.2. I deployed a new server with PostgreSQL and I use Filebeat to send PostgreSQL logs the the elasticsearch cluster. I added the pluggin PostgreSQL and imported the dashboard (filebeat setup -e).

Dont have:  
Query count and cumulated duration [Filebeat PostgreSQL]  
Query Durations [Filebeat PostgreSQL]  
Slow Queries [Filebeat PostgreSQL]

cat modules.d/postgresql.yml

```
- module: postgresql
  # All logs
  log:
    enabled: true

    var.paths:
     - /var/lib/pgsql/11/data/log/*.log

```

cat /var/lib/pgsql/11/data/postgresql.conf | grep -v "^#" | grep -v "^$"

```
max_connections = 100 
shared_buffers = 128MB
dynamic_shared_memory_type = posix 
max_wal_size = 1GB
min_wal_size = 80MB
log_destination = 'stderr'
logging_collector = on
log_directory = 'log' 
log_filename = 'postgresql-%a.log' 
log_truncate_on_rotation = on 
log_rotation_age = 1d 
log_rotation_size = 0 
log_duration = on
log_line_prefix = '%m [%p] '
log_timezone = 'W-SU'
datestyle = 'iso, mdy'
timezone = 'W-SU'
lc_messages = 'en_US.UTF-8' 
lc_monetary = 'en_US.UTF-8' 
lc_numeric = 'en_US.UTF-8'
lc_time = 'en_US.UTF-8' 
default_text_search_config = 'pg_catalog.english'

```

 ![%D0%A1%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA%20%D1%8D%D0%BA%D1%80%D0%B0%D0%BD%D0%B0%20%D0%BE%D1%82%202019-03-26%2008-33-24](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d1cafe505e0d5fcadec50dfea315271f26e56db0.png)

 ![%D0%A1%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA%20%D1%8D%D0%BA%D1%80%D0%B0%D0%BD%D0%B0%20%D0%BE%D1%82%202019-03-26%2008-33-38](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28b09ab36a7edae1f33685cb5e7e657594f899bd.png)

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 25, 2019, 5:35pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799/2 "2019-03-25T17:35:47Z")

</div>

I am not sure I understand your problem. Could you please provide more information?

---

<div class="post-metadata">

**Author:** ![patsevanton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patsevanton/32/42692_2.png) [@patsevanton](https://discuss.elastic.co/u/patsevanton)\
**Post date:** [March 27, 2019, 8:18am UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799/4 "2019-03-27T08:18:09Z")

</div>

Can you send example postgresql.conf for parse log of Filebeat?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 27, 2019, 3:18pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799/5 "2019-03-27T15:18:20Z")

</div>

Your configuration is correct.

---

<div class="post-metadata">

**Author:** ![fredgalvao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fredgalvao/32/42048_2.png) [@fredgalvao](https://discuss.elastic.co/u/fredgalvao)\
**Post date:** [March 27, 2019, 11:05pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799/6 "2019-03-27T23:05:20Z")

</div>

I'm having an even harder time getting this to work for me. Grok can't understand logs from the default PostgreSQL@11 pattern, no matter how I setup `log_line_prefix`. I have tried:

- empty/default
- `'%m [%p] '` like the OP
- `'%t [%p]: [%l-1] user=%u,db=%d,client=%h,appname=%a'` like used in production for me

I was hoping the default-everything would "just work ©". I went through all of 7.0.0-rc1 beat docs and found nothing about _having_ to specify log pattern for grok, not even _how to do it_.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 11:05pm UTC](https://discuss.elastic.co/t/dont-have-query-count-and-cumulated-duration-filebeat-postgresql/173799/7 "2019-04-24T23:05:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
