# Elasticsearch + MySQL

**URL:** <https://discuss.elastic.co/t/elasticsearch-mysql/158211>\
**Category:** Elasticsearch\
**Created:** [November 26, 2018, 3:31pm UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211 "2018-11-26T15:31:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [November 26, 2018, 3:31pm UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/1 "2018-11-26T15:31:57Z")

</div>

Hello,  
Getting logs from ntopng - was thinking sending it to MySQL and then using Elasticsearch to query it and obviously visualize it in Kibana.  
Is this ideal? Im looking to keep 1 year worth of logs. On top of ntopng logs I will have cisco and winevt.  
I was suggested to just send the logs directly to Elasticsearch rather than using MySQL - what's the downside to this?  
Cheers

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 26, 2018, 10:55pm UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/2 "2018-11-26T22:55:34Z")

</div>

The downside is you have another system to maintain.  
There are plenty of upside though.

---

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [November 27, 2018, 9:20am UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/3 "2018-11-27T09:20:23Z")

</div>

You mean if I go with MySQL I will have one more system to maintain? Fair enough, but what would be big upside to this? I'm trying to get as much perspective as I can before moving in with this. Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 28, 2018, 1:39am UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/4 "2018-11-28T01:39:22Z")

</div>

Fast, customisable search that's built for search and not just a table scan. Plus a whole bunch of analytics that can be API or Kibana driven. Native geospatial datasets and queries.

And then there things like Machine Learning and Alerting which add a heap of extra value.

---

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [November 28, 2018, 10:20am UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/5 "2018-11-28T10:20:13Z")

</div>

Okay, so let me get this straight - is it possible to do this:  
ntopng \> mysql \> elasticsearch \> kibana  
Use MySQL to store data and Elasticsearch to query data? or should I just do this:  
ntopng \> elasticsearch \> kibana  
I have been getting some information on Graylog and apparently its impossible to do what I mentioned (ntopng \> mysql \> elasticsearch \> graylog) and instead I should do:  
ntopng \> logstash \> graylog \> elasticsearch.  
Also I heard with MySQL the search would be slower and that with ES it'd be faster.  
Opinions?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 28, 2018, 8:35pm UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/6 "2018-11-28T20:35:23Z")

</div>

I'm not familiar with ntopng, but if it can send direct to Elasticsearch then I would just do that.  
Also Graylog uses Elasticsearch, so you wouldn't have any further steps once it got there.

Yes, Elasticsearch search will be much faster than MySQL.

---

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [November 30, 2018, 11:42am UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/7 "2018-11-30T11:42:48Z")

</div>

I apologize for this post. My original intention was mislead by a colleague.  
Anyhow, since we are here. I was wondering if I have Graylog doing all the logging (ntopng + winevt + cisco) and I have Kibana installed on the same server. Will I then be able to use Kibana only for its visualization?  
My intention is: Graylog for logging | Kibana for visualization.  
Since all the logging from Graylog will be stored in ES, if I have Kibana installed - surely it will pick up these logs?  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 1, 2018, 3:56am UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/8 "2018-12-01T03:56:43Z")

</div>

> [@Marcos\_Felix](#):
>
> Will I then be able to use Kibana only for its visualization?

I believe you can do this, yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2018, 4:00am UTC](https://discuss.elastic.co/t/elasticsearch-mysql/158211/9 "2018-12-29T04:00:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
