# Can't get the value from mysql-slow.log

**URL:** <https://discuss.elastic.co/t/cant-get-the-value-from-mysql-slow-log/69126>\
**Category:** Logstash\
**Created:** [December 15, 2016, 8:06am UTC](https://discuss.elastic.co/t/cant-get-the-value-from-mysql-slow-log/69126 "2016-12-15T08:06:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![houfan](https://avatars.discourse-cdn.com/v4/letter/h/47e85d/32.png) [@houfan](https://discuss.elastic.co/u/houfan)\
**Post date:** [December 15, 2016, 8:06am UTC](https://discuss.elastic.co/t/cant-get-the-value-from-mysql-slow-log/69126/1 "2016-12-15T08:06:50Z")

</div>

input :

# Query\_time: 0.000148 Lock\_time: 0.000023 Rows\_sent: 0 Rows\_examined: 202

grok pattern is :

# Query\_time: %{NUMBER:query\_time:float}\s+Lock\_time: %{NUMBER:lock\_time:float}\s+Rows\_sent: %{NUMBER:rows\_sent:int}\s+Rows\_examined: %{NUMBER:rows\_examined:int}

and the grok debugger give me this output:

{  
"BASE10NUM": [  
[  
"0.000148",  
"0.000023",  
"0",  
"202"  
]  
]  
}

I didn't keep empty captures.when I modify the pattern like this :

# Query\_time: %{NUMBER:query\_time}\s+Lock\_time: %{NUMBER:lock\_time}\s+Rows\_sent: %{NUMBER:rows\_sent}\s+Rows\_examined: %{NUMBER:rows\_examined}

and this comes out:  
{  
"query\_time": [  
[  
"0.000148"  
]  
],  
"BASE10NUM": [  
[  
"0.000148",  
"0.000023",  
"0",  
"202"  
]  
],  
"lock\_time": [  
[  
"0.000023"  
]  
],  
"rows\_sent": [  
[  
"0"  
]  
],  
"rows\_examined": [  
[  
"202"  
]  
]  
}

is this the right pattern??? and where did this "BASE10NUM" come from???  
eeeee.....really,really thanks for your help:sob:

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 19, 2016, 1:42am UTC](https://discuss.elastic.co/t/cant-get-the-value-from-mysql-slow-log/69126/2 "2016-12-19T01:42:25Z")

</div>

Please format your code using the `</>` button, it's kinda hard to read otherwise 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2017, 1:42am UTC](https://discuss.elastic.co/t/cant-get-the-value-from-mysql-slow-log/69126/3 "2017-01-16T01:42:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
