# Filter postgresql ERROR, FATAL, PANIC messages from postgresql logs

**URL:** <https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843>\
**Category:** Logstash\
**Created:** [March 30, 2021, 9:47pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843 "2021-03-30T21:47:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk\_newbie](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@elk\_newbie](https://discuss.elastic.co/u/elk_newbie)\
**Post date:** [March 30, 2021, 9:47pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843/1 "2021-03-30T21:47:10Z")

</div>

Hi community,

Is there any way to filter **only** ERROR, FATAL and PANIC messages from Postgresql logs?

appreciate any help!

Regards  
Patrick

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 30, 2021, 10:22pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843/2 "2021-03-30T22:22:53Z")

</div>

Assuming you have the log level at the front of the message followed by a colon you could do it using

```
dissect { mapping => { "message" => "%{[@metadata][loglevel]}: %{}" } }
if [@metadata][loglevel] not in ["ERROR", "FATAL", "PANIC"] { drop {} }
```

---

<div class="post-metadata">

**Author:** ![elk\_newbie](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@elk\_newbie](https://discuss.elastic.co/u/elk_newbie)\
**Post date:** [March 30, 2021, 10:48pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843/3 "2021-03-30T22:48:48Z")

</div>

Hi Badger, thanks for your tip!

The logs look like the following:

FATAL:  
\< 2021-03-14 20:51:01.683 CET ngapp sup1 [unknown] 18825 \> FATAL: remaining connection slots are reserved for non-replication superuser connections

ERROR:  
\< 2021-03-30 00:18:59.623 CEST ngapp sup1 AppT 31253 \> ERROR: column table.col6 does not exist at character 783  
\< 2021-03-30 00:18:59.623 CEST ngapp sup1 AppT 31253 \> STATEMENT: select table.col1 as col\_1\_, table.col2 as col\_2, table.col6 as col\_6 from Table table where table.col4=$1

I would need to catch the STATEMENT as well.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 30, 2021, 11:00pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843/4 "2021-03-30T23:00:59Z")

</div>

OK, so I would probably adjust the dissect to be

```
dissect { mapping => { "message" => "< %{[@metadata][timestamp]} %{+[@metadata][timestamp]} %{+[@metadata][timestamp]} %{appname} %{field1} [%{field2}] %{number} > %{loglevel}: %{logMessage}"

```

If you want to keep the STATEMENT line then add "STATEMENT" to the array with the others

```
if [loglevel] not in ["ERROR", "FATAL", "PANIC", "STATEMENT"] { drop {} }

```

The joda timezone page does not list CEST as one it supports (it does support CET) so I would parse the date using

```
mutate {
    gsub => [
        "[@metadata][timestamp]", " CEST$", " +02:00",
        "[@metadata][timestamp]", " CET$", " +01:00" ]
    ]
}
date { match => ["[@metadata][timestamp]", "YYYY-MM-dd HH:mm:ss.SSS ZZ" ] }
```

---

<div class="post-metadata">

**Author:** ![elk\_newbie](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@elk\_newbie](https://discuss.elastic.co/u/elk_newbie)\
**Post date:** [March 31, 2021, 6:46pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843/5 "2021-03-31T18:46:21Z")

</div>

Thanks a lot for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2021, 6:46pm UTC](https://discuss.elastic.co/t/filter-postgresql-error-fatal-panic-messages-from-postgresql-logs/268843/6 "2021-04-28T18:46:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
