# PostgreSQL Module: What is the "EXPECTED" format (I.E. postgresql.conf settings)

**URL:** <https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 30, 2019, 4:34pm UTC](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916 "2019-10-30T16:34:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Larry\_Rosenman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_rosenman/32/56877_2.png) [@Larry\_Rosenman](https://discuss.elastic.co/u/Larry_Rosenman)\
**Post date:** [October 30, 2019, 4:34pm UTC](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916/1 "2019-10-30T16:34:51Z")

</div>

for the filebeat PostgreSQL module, what are the expected settings in postgresql.conf (for the PostgreSQL server) on the logging related parameters, Prefix, etc.

I've searched and searched and would love to have this documented, especially for PostgreSQL 11.x

---

<div class="post-metadata">

**Author:** ![Muckis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muckis/32/56905_2.png) [@Muckis](https://discuss.elastic.co/u/Muckis)\
**Post date:** [October 31, 2019, 3:52am UTC](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916/2 "2019-10-31T03:52:43Z")

</div>

Hi,

This is the grok filter used by the posgresql module:  
"grok" : {  
"patterns" : [  
"""^%{DATETIME:postgresql.log.timestamp} [%{NUMBER:process.pid:long}(-%{BASE16FLOAT:postgresql.log.core\_id:long})?] (([%{USERNAME:user.name}]@[%{POSTGRESQL\_DB\_NAME:postgresql.log.database}]|%{USERNAME:user.name}@%{POSTGRESQL\_DB\_NAME:postgresql.log.database}) )?%{WORD:log.level}: (duration: %{NUMBER:temp.duration:float} ms statement: %{GREEDYDATA:postgresql.log.query}|%{GREEDYDATA:message})"""  
],  
I hope this help to show what the module expects.

Cheers

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 31, 2019, 7:50am UTC](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916/3 "2019-10-31T07:50:11Z")

</div>

Filebeat modules usually parse the output of the default format. Is that not working in your case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2019, 7:50am UTC](https://discuss.elastic.co/t/postgresql-module-what-is-the-expected-format-i-e-postgresql-conf-settings/205916/4 "2019-11-28T07:50:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
