# Logstash 對於 postgresql log的filter 問題

**URL:** https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816
**Category:** 中文提问与讨论
**Created:** [October 5, 2017, 9:16am UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816 "2017-10-05T09:16:40Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![stephen\_luan](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@stephen\_luan](https://discuss.elastic.co/u/stephen_luan)
#### Post date: [October 5, 2017, 9:16am UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816/1 "2017-10-05T09:16:40Z")

</div>

Hi All,  
不知道這裡有沒有人使用logstash , 把postgresql log 做fileter, 找了很多方法，都無法實現，postgresql log 大致如下， 不知道各位有沒有比較好的解決方法

2017-10-02 16:00:06 CST[2017-10-02 15:59:13 CST]59d1f1d1.61ad[25005]10.0.10.\* username || LOG: duration: 9904.724 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:00:06 CST[2017-10-02 15:59:13 CST]59d1f1d1.61ad[25005]10.0.10.\* username || DETAIL: parameters: $1 = '1'  
2017-10-02 16:00:07 CST[2017-10-02 15:59:45 CST]59d1f1f1.63f4[25588]10.0.10.\* username || LOG: duration: 14514.898 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:00:07 CST[2017-10-02 15:59:45 CST]59d1f1f1.63f4[25588]10.0.10.\* username || DETAIL: parameters: $1 = '_ **', $2 = '2', $3 = '3', $4 = '6', $5 = '4', $6 = '20171002', $7 = '20180102', $8 = '**', $9 = '__'  
2017-10-02 16:00:50 CST[2017-10-02 16:00:34 CST]59d1f222.6808[26632]10.0.10. username || LOG: duration: 15381.794 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:00:50 CST[2017-10-02 16:00:34 CST]59d1f222.6808[26632]10.0.10._ username || DETAIL: parameters: $1 = ' **', $2 = '** _', $3 = '**', $4 = '20171009'  
2017-10-02 16:00:54 CST[2017-10-02 16:00:13 CST]59d1f20d.6665[26213]10.0.10. username || LOG: duration: 14386.347 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:00:54 CST[2017-10-02 16:00:13 CST]59d1f20d.6665[26213]10.0.10. username || DETAIL: parameters: $1 = ''  
2017-10-02 16:01:32 CST[2017-10-02 16:00:41 CST]59d1f229.68b8[26808]10.0.10. username || LOG: duration: 47126.369 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:01:32 CST[2017-10-02 16:00:41 CST]59d1f229.68b8[26808]10.0.10. username || DETAIL: parameters: $1 = '', $2 = '', $3 = '', $4 = '20171109'  
2017-10-02 16:01:38 CST[2017-10-02 16:01:11 CST]59d1f247.6b8a[27530]10.0.10. username || LOG: duration: 7699.837 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:01:38 CST[2017-10-02 16:01:11 CST]59d1f247.6b8a[27530]10.0.10. username || DETAIL: parameters: $1 = '23018', $2 = '00', $3 = '10', $4 = '', $5 = '', $6 = '', $7 = '', $8 = '', $9 = '', $10 = '10', $11 = '15', $12 = '20', $13 = '90', $14 = '', $15 = '', $16 = '', $17 = '', $18 = '20170715', $19 = '20180102'  
2017-10-02 16:01:41 CST[2017-10-02 15:59:36 CST]59d1f1e8.6336[25398]10.0.10. username || LOG: duration: 123312.666 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:01:41 CST[2017-10-02 15:59:36 CST]59d1f1e8.6336[25398]10.0.10. username || DETAIL: parameters: $1 = '', $2 = '**_', $3 = '_', $4 = '20171006'  
2017-10-02 16:02:23 CST[2017-10-02 16:01:11 CST]59d1f247.6b84[27524]10.0.10. username || LOG: duration: 67953.366 ms execute : select \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
2017-10-02 16:02:23 CST[2017-10-02 16:01:11 CST]59d1f247.6b84[27524]10.0.10. username || DETAIL: parameters: $1 = '20170901', $2 = '_ **', $3 = '** \*\*\*\*', $4 = '\ ***', $5 = '**'

---

<div class="post-metadata">

### Author: ![medcl.net](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/medcl.net/32/4414_2.png) [@medcl.net](https://discuss.elastic.co/u/medcl.net)
#### Post date: [October 31, 2017, 12:52pm UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816/2 "2017-10-31T12:52:46Z")

</div>

Hi, 看你的日志，主要目的是要进行结构化么，你说的 filter 是指 Grok 抽取字段么？还是其他需求？

---

<div class="post-metadata">

### Author: ![stephen\_luan](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@stephen\_luan](https://discuss.elastic.co/u/stephen_luan)
#### Post date: [November 2, 2017, 12:50am UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816/3 "2017-11-02T00:50:16Z")

</div>

Hi , 我主要的目的確實要進行結構化，並且利用elasticsearch 及kibana來分析。

---

<div class="post-metadata">

### Author: ![medcl.net](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/medcl.net/32/4414_2.png) [@medcl.net](https://discuss.elastic.co/u/medcl.net)
#### Post date: [November 12, 2017, 1:50am UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816/4 "2017-11-12T01:50:13Z")

</div>

如果是结构化，用 Grok filter 就可以实现的。

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 10, 2017, 1:50am UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816/5 "2017-12-10T01:50:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
