# Support to normalize query params in postgresql module in filebeat

**URL:** <https://discuss.elastic.co/t/support-to-normalize-query-params-in-postgresql-module-in-filebeat/126312>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 31, 2018, 9:50am UTC](https://discuss.elastic.co/t/support-to-normalize-query-params-in-postgresql-module-in-filebeat/126312 "2018-03-31T09:50:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vjay\_Jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjay_jain/32/29431_2.png) [@Vjay\_Jain](https://discuss.elastic.co/u/Vjay_Jain)\
**Post date:** [March 31, 2018, 9:50am UTC](https://discuss.elastic.co/t/support-to-normalize-query-params-in-postgresql-module-in-filebeat/126312/1 "2018-03-31T09:50:05Z")

</div>

Hi Team,

I have a project to send postgresql logs to ELK.  
i have tried using a setup to parse through postgres logs and send them to elasticsearch until i saw filebeat can now support postgresql logs.

now there are concerns that postgresql logging may log queries which are problematic and that may contain sensitive data as insert/update params.

i saw this extension (in ruby but there is a similar one in go) that can mask params in the query.

> **[lfittl/pg\_query](https://github.com/lfittl/pg_query#parsing-a-normalized-query)**
>
> pg\_query - Ruby extension to parse, deparse and normalize SQL queries using the PostgreSQL query parser

i guess sometime later, this module will have to anonymize the query params for the sake of security/GDPR etc.

can this be done at filebeat level?  
i even thought of doing it at the logstash level, but looks like jruby does not like c extensions ☹

> <https://gist.github.com/cabecada/dd765a30f6946fdbf0bec0eb31fba047>

any help or guidance would be appreciated.

Thanks,  
Vijay

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [April 2, 2018, 12:51pm UTC](https://discuss.elastic.co/t/support-to-normalize-query-params-in-postgresql-module-in-filebeat/126312/2 "2018-04-02T12:51:52Z")

</div>

HI Vjay,

The [Go library](https://github.com/lfittl/pg_query_go) looks good for this task. Can you open an [Enhancement Request](https://github.com/elastic/beats/issues/new) with this idea? I'd like someone from the infrastructure functional area to review this library and see if there is a problem integrating it with filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2018, 12:51pm UTC](https://discuss.elastic.co/t/support-to-normalize-query-params-in-postgresql-module-in-filebeat/126312/3 "2018-04-30T12:51:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
