# Elasticsearch Postgresql Module Ingest Pipeline Not Parsing Postgresql 10

**URL:** <https://discuss.elastic.co/t/elasticsearch-postgresql-module-ingest-pipeline-not-parsing-postgresql-10/287604>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [October 25, 2021, 4:09pm UTC](https://discuss.elastic.co/t/elasticsearch-postgresql-module-ingest-pipeline-not-parsing-postgresql-10/287604 "2021-10-25T16:09:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [October 25, 2021, 4:09pm UTC](https://discuss.elastic.co/t/elasticsearch-postgresql-module-ingest-pipeline-not-parsing-postgresql-10/287604/1 "2021-10-25T16:09:02Z")

</div>

Elasticsearch ingest pipeline for `postgresql` module doesn't appear to parse postgresql 10 logs. This is with `filebeat-7.15.0` and associated ingest pipelines under `elasticsearch-7.14.1`.

We're using Postgresql 10. The following log entry:

```auto
2021-10-25 10:38:30.009 CDT [15176] postgres_user postgres PerMin:server001Test001 10.121.192.106(50637) LOG: AUDIT: SESSION,1950,1,MISC,UNKNOWN,VIEW,public.pg_stat_statements,"select query, sum(calls) as calls, cast(sum(total_time * 1000) as bigint) as total_time, sum(rows) as rows, sum(shared_blks_hit) as shared_blks_hit, sum(shared_blks_read) as shared_blks_read, sum(shared_blks_written) as shared_blks_written from pg_stat_statements group by query, dbid",<none>

```

generates the following error:

```auto
Provided Grok expressions do not match field value: [[15176] postgres_user postgres PerMin:server001Test001 10.121.192.106(50637) LOG: AUDIT: SESSION,1950,1,MISC,UNKNOWN,VIEW,public.pg_stat_statements,\"select query, sum(calls) as calls, cast(sum(total_time * 1000) as bigint) as total_time, sum(rows) as rows, sum(shared_blks_hit) as shared_blks_hit, sum(shared_blks_read) as shared_blks_read, sum(shared_blks_written) as shared_blks_written from pg_stat_statements group by query, dbid\",<none>]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2021, 4:09pm UTC](https://discuss.elastic.co/t/elasticsearch-postgresql-module-ingest-pipeline-not-parsing-postgresql-10/287604/2 "2021-11-22T16:09:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
