Postgresql grpk pattern error fb 6.4


(Brian Hansen) #1

Hello,
I am using filebeat 6.4 with the postgresql module installed and pointed at my pg_log folder, and it is shipping the logs but I am getting a GROK parse error
the system is centos 7 installed with the filebeat 6.4 rpm Postgresql version is 9.6.6 and my logs look like this

< 2018-09-14 11:33:46.724 PDT > LOG: connection authorized: user=xxxxx database=xxxxx

the error I am getting is Provided Grok expressions do not match field value:


(Jaime Soriano) #2

Hi @bhansen and welcome :slight_smile:

Your log line looks fine, but the date seems enclosed between < and >, is it like this in your log file? This is not expected in the grok patterns. Have you customized the log configuration in some way?


(Brian Hansen) #3

I have not it was installed, then I turned on some of the logging features like log connections etc. each line of the log starts with
< 2018-09-17 08:08:47.420 PDT > LOG: connection received: host=npt-app-09.main.popud.org port=43502
< 2018-09-17 08:08:47.421 PDT > LOG: connection received: host=npt-app-09.main.popud.org port=43500
< 2018-09-17 08:08:47.423 PDT > LOG: connection received: host=npt-app-09.main.popud.org port=43504


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.