# Provided Grok expressions do not match field value when using postgres log

**URL:** <https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-when-using-postgres-log/199404>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 13, 2019, 9:50am UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-when-using-postgres-log/199404 "2019-09-13T09:50:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![oobi89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oobi89/32/78396_2.png) [@oobi89](https://discuss.elastic.co/u/oobi89)\
**Post date:** [September 13, 2019, 9:50am UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-when-using-postgres-log/199404/1 "2019-09-13T09:50:47Z")

</div>

Hello,  
I've configured Filebeats to get logs from postgres, send it to elasticsearch and then display them in kibana.

Logs are send successfully to Elasticsearch, when I go to Kibana\>Discovery I receive error:  
`# [Index has exceeded [xxx] - maximum allowed to be analyzed for highlighting](https://discuss.elastic.co/t/index-has-exceeded-xxx-maximum-allowed-to-be-analyzed-for-highlighting/199303)`  
I've managed to turn off that error using advanced Kibana settings and set doc\_table:highlight to false.

The thing is, when I go to Discover now I see some error in error.message field:  
`Provided Grok expressions do not match field value: [< 2018-03-27 09:48:04.468 CEST > LOG: could not receive data from client: Connection reset by peer]`

and the log message is just:  
`2018-03-27 09:48:04.468 CEST > LOG: could not receive data from client: Connection reset by peer`

So I was thinking that maybe that this 2 issues are connected and I get that exceeded error because Filebeat cant pare timestamp correctly ?

Anyway, how should I fixed it ?  
I was thinking that timestamp from logs can be parsed and used in index to sort entries by it, instead it takes timestamp of when the file was loaded into elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2019, 9:51am UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-when-using-postgres-log/199404/2 "2019-10-11T09:51:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
