# Elasticsearch Query Monitoring

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584>\
**Category:** Elasticsearch\
**Created:** [April 5, 2019, 11:55am UTC](https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584 "2019-04-05T11:55:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vikash\_Kumar1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_kumar1/32/42775_2.png) [@Vikash\_Kumar1](https://discuss.elastic.co/u/Vikash_Kumar1)\
**Post date:** [April 5, 2019, 11:55am UTC](https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584/1 "2019-04-05T11:55:54Z")

</div>

Hi All,

I am using elasticsearch and looking for a way to get all the queries which are getting executed in the elasticsearch. Basically I want to log all the queries.  
I read that one way is that we can decrease the threshold value of the slow log query so that it will start logging into the log file.

But the above approach will result in writing too many logs and I fear it might effect the performance,

Is there a better way to log all the queries?

Thanks in advance,  
Vikash

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [April 6, 2019, 8:11am UTC](https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584/2 "2019-04-06T08:11:49Z")

</div>

You can use [Packetbeat](https://www.elastic.co/products/beats/packetbeat) to [capture the http requests](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-http-options.html) being sent to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Vikash\_Kumar1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_kumar1/32/42775_2.png) [@Vikash\_Kumar1](https://discuss.elastic.co/u/Vikash_Kumar1)\
**Post date:** [April 10, 2019, 8:04am UTC](https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584/3 "2019-04-10T08:04:32Z")

</div>

Hey Abdon,

Thanks for the response. I implemented packetbeats but it gave me the below results:

1. http error codes
2. http codes
3. Total number of HTTP transactions

However, it didn't gave me the on-going Elasticsearch search queries that is currently happening on my ES cluster.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [April 11, 2019, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584/4 "2019-04-11T06:10:54Z")

</div>

You need to configure Packetbeat to capture the data that you need. In the packetbeat.yml configuration file, you should set [`include_body_for`](https://www.elastic.co/guide/en/beats/packetbeat/master/packetbeat-http-options.html#_literal_include_body_for_literal) to capture the body of the http requests and responses:

```auto
- type: http
  # Configure the ports where to listen for HTTP traffic. You can disable
  # the HTTP protocol by commenting out the list of ports.
  ports: [9200]
  include_body_for: ["application/json"]

```

What you probably also will want to do is remove all requests to any URL that do not contain "`_search`" (as you're only interested in the queries). To do that, you could configure the following processor in the packetbeat.yml file:

```auto
processors:
  - drop_event:
      when:
        not:
          contains:
            url.path: "_search"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2019, 6:11am UTC](https://discuss.elastic.co/t/elasticsearch-query-monitoring/175584/5 "2019-05-09T06:11:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
