# Packetbeat postgresql

**URL:** <https://discuss.elastic.co/t/packetbeat-postgresql/127577>\
**Category:** Beats\
**Created:** [April 11, 2018, 6:30am UTC](https://discuss.elastic.co/t/packetbeat-postgresql/127577 "2018-04-11T06:30:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [April 11, 2018, 6:30am UTC](https://discuss.elastic.co/t/packetbeat-postgresql/127577/1 "2018-04-11T06:30:05Z")

</div>

Hallo,

I experience some funny errors when dealing with packetbeat and the postgresql module.  
First of all, I can see Data being send to Elasticsearch and I can view them in Kibana.  
Secondly, I think it is more a bug than a configuration error. Postgresql has about 250.000 queries per second, but I only get a few 100 lines per second send into my elasticsearch. Even when looking for an average over 15 Minutes, there are millions of lines missing.

How can I tackle this? Anybody an Idea what I can turn off / turn on in packetbeat to see why it is failing? I can find the following lines in the /var/log/packetbeat/packetbeat

> 2018-04-11T08:28:20.572+0200 WARN pgsql/parse.go:501 Pgsql parser expected data message, but received command of type 110  
> 2018-04-11T08:28:30.193+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=13, i=8  
> 2018-04-11T08:28:30.262+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=28, i=8  
> 2018-04-11T08:28:32.742+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=138, i=3  
> 2018-04-11T08:28:33.424+0200 WARN pgsql/parse.go:501 Pgsql parser expected data message, but received command of type 110  
> 2018-04-11T08:28:33.425+0200 WARN pgsql/parse.go:501 Pgsql parser expected data message, but received command of type 110  
> 2018-04-11T08:28:34.192+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=150, i=3  
> 2018-04-11T08:28:36.205+0200 WARN pgsql/parse.go:501 Pgsql parser expected data message, but received command of type 110  
> 2018-04-11T08:28:39.486+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=22, i=4  
> 2018-04-11T08:28:39.488+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=60, i=4  
> 2018-04-11T08:28:39.491+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=60, i=4  
> 2018-04-11T08:28:39.492+0200 ERROR pgsql/parse.go:531 Pgsql invalid column\_length=4294967295, buffer\_length=60, i=4

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 13, 2018, 1:28pm UTC](https://discuss.elastic.co/t/packetbeat-postgresql/127577/2 "2018-04-13T13:28:00Z")

</div>

There's probably some packet loss affecting Packetbeat's ability to reconstruct the postgres data. There's a metric that is logged at 30s intervals that indicates how many packets have been dropped. This happens when there's more data coming in that can be processed.

What are your settings in Packetbeat's config? If you are Linux try using af\_packet and [tuning some settings](https://www.elastic.co/guide/en/beats/packetbeat/6.2/configuration-interfaces.html#_sniffing_configuration_options).

```auto
packetbeat.interfaces.device: eth0 # Don't use 'any'. Listen specifically on one interface.
packetbeat.interfaces.snaplen: 1514
packetbeat.interfaces.type: af_packet
packetbeat.interfaces.buffer_size_mb: 100

```

Disable flows if you aren't using them.

```auto
packetbeat.flows.enabled: false 

```

And disable other protocols that you are not using. This will limit the amount of packets that Packetbeat is receiving such that it can use its resources for postgres data only.

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [April 14, 2018, 1:03pm UTC](https://discuss.elastic.co/t/packetbeat-postgresql/127577/3 "2018-04-14T13:03:41Z")

</div>

Thanks for the information with the `buffer_size_mb`, that really help it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2018, 3:03pm UTC](https://discuss.elastic.co/t/packetbeat-postgresql/127577/4 "2018-05-12T15:03:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
