# How can we moniter MySql port 3306 and Postgresql port 5432 in windows

**URL:** <https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 16, 2017, 9:11am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886 "2017-05-16T09:11:08Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [May 16, 2017, 9:11am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/1 "2017-05-16T09:11:09Z")

</div>

Dears

I wanted to get monitor from MySQL(3306) or PostgreSQL(5432) in windows 10 os  
I have created inbound and outbound about 3306 and 5432 ports

I set configuration in packetbeat.yml like  
packetbeat.interfaces.device: 0

packetbeat.protocols.http:  
ports: [80, 8080, 8000, 5000, 8002, 8099]

packetbeat.protocols.mysql:  
ports: [3306]

packetbeat.protocols.pgsql:  
ports: [5432]

output.elasticsearch:  
hosts: ["127.0.0.1:9200"]

I have installed Npcap also

After start ElasticSearch, Kibana and PacketBeat, I couldn"t receive packets from 3306 and 5432 ports, the same I can able to get packets from 8099(Tomcat)

Is there any thing need to set for windows?

Thanks & Regards,  
Nagarajan.H

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 16, 2017, 11:10am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/2 "2017-05-16T11:10:07Z")

</div>

Windows doesn't really support localhost capturing. [This ticket](https://github.com/elastic/beats/issues/104) recommends [npcap](https://github.com/nmap/npcap/releases).

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 16, 2017, 12:36pm UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/3 "2017-05-16T12:36:38Z")

</div>

> [@Harinagarajan](#):
>
> packetbeat.interfaces.device: 0

Are you sure you are listening on the correct device? You can list the devices with `.\packetbeat.exe -devices`.

---

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [May 17, 2017, 2:04am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/4 "2017-05-17T02:04:36Z")

</div>

> [@andrewkroh](#):
>
> .\packetbeat.exe -devices

if we put .\packetbeat.exe -devices command means

0: \Device\NPF\_{5BC8D54F-F098-49C3-8D2D-969E839DFA8E} (Intel(R) Ethernet Connection I219-V) (fe80::79b6:7ad7:e5c6:9de9  
192.168.2.120)  
1: \Device\NPF\_{11FF37BF-069C-481D-8EEE-1E1FB9BD69F6} (Microsoft) (fe80::dfa:60ab:c73d:87c7 2408:210:28ec:b800:24d7:cd  
1e:56aa:e45d 2408:210:28ec:b800:dfa:60ab:c73d:87c7 192.168.2.100)

is coming in powershell command prompt

I have set  
packetbeat.interfaces.device: 0

---

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [May 17, 2017, 2:09am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/6 "2017-05-17T02:09:46Z")

</div>

Thank You Very Much For The Information

---

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [May 18, 2017, 4:53am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/7 "2017-05-18T04:53:12Z")

</div>

Dear

I did based on

> <https://github.com/elastic/beats/issues/104>

so that I can able to get

PS C:\Program Files\Packetbeat\> .\packetbeat.exe -devices  
0: \Device\NPF\_{5BC8D54F-F098-49C3-8D2D-969E839DFA8E} (Intel(R) Ethernet Connection I219-V) (fe80::79b6:7ad7:e5c6:9de9  
192.168.2.120)  
1: \Device\NPF\_{11FF37BF-069C-481D-8EEE-1E1FB9BD69F6} (Microsoft) (fe80::dfa:60ab:c73d:87c7 2408:210:28ec:b800:ac86:cc  
08:6354:2d1f 2408:210:28ec:b800:dfa:60ab:c73d:87c7 192.168.2.100)  
2: \Device\NPF\_{AA15BD21-3348-460A-8081-023207EABD27} (MS NDIS 6.0 LoopBack Driver) (fe80::f180:c469:a35a:4b9e 0.0.0.0  
)

in powershell command prompt, and I configured as 2 in packetbeat.yml file too

if we are execute the sql query from MySQL means, Wireshark receiving the packets

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb128458b2eb1994f90e5010453d52a6a1280f55.png)

the same I couldn"t get any packets in kibana

what can I do as settings

Thanks & Regards,  
Nagarajan.H

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 19, 2017, 12:17pm UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/8 "2017-05-19T12:17:09Z")

</div>

If the traffic is coming in on the loopback device then using the device number 2 should get you the mysql traffic.

Please repost your latest config file. Use the `</>` button to get it formatted.

You could enable debug logging and see if there is anything interesting in the logs. Add `logging.level: debug` to your config.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 19, 2017, 12:57pm UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/9 "2017-05-19T12:57:28Z")

</div>

For mysql I would also look out for flows being reported on this port. The mysql analyzer does not support all MYSQL transaction types. If flows are present, but mysql transactions are missing, it's likely due to unsupported transaction types. The analyzer will also print a message when debug is enabled.

---

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [May 23, 2017, 4:17am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/10 "2017-05-23T04:17:26Z")

</div>

Hi, now i am using  
packetbeat.interfaces.device: 2  
ports: [80, 8080, 8000, 5000, 8002, 8099]  
ports: [3306]  
ports: [5432]  
logging.level: debug

only, even though I couldn't receive any 3306 and 5432 ports logs

---

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [May 23, 2017, 4:23am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/11 "2017-05-23T04:23:19Z")

</div>

The same I tried in PostgreSQL also, can you tell some of supported transaction by packetbeat , I have tried with insert data and retriew data from MySQL/PostgreSQL

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 6, 2017, 8:44am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/12 "2017-06-06T08:44:28Z")

</div>

simple SELECT and INSERT statements should work fine with MySQL and PostgreSQL. Enabling/using the flows feature gives you an idea if any packets have been processed for these ports.

Which IPs do your services have? Which IPs do your network interfaces have?

---

<div class="post-metadata">

**Author:** ![Harinagarajan](https://avatars.discourse-cdn.com/v4/letter/h/f05b48/32.png) [@Harinagarajan](https://discuss.elastic.co/u/Harinagarajan)\
**Post date:** [June 7, 2017, 1:59am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/13 "2017-06-07T01:59:06Z")

</div>

I am developing in local system which connected in internet

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 1:59am UTC](https://discuss.elastic.co/t/how-can-we-moniter-mysql-port-3306-and-postgresql-port-5432-in-windows/85886/14 "2017-07-05T01:59:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
