# How parse mysql slow queries into elastic

**URL:** <https://discuss.elastic.co/t/how-parse-mysql-slow-queries-into-elastic/302364>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 13, 2022, 4:01pm UTC](https://discuss.elastic.co/t/how-parse-mysql-slow-queries-into-elastic/302364 "2022-04-13T16:01:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [April 13, 2022, 4:01pm UTC](https://discuss.elastic.co/t/how-parse-mysql-slow-queries-into-elastic/302364/1 "2022-04-13T16:01:24Z")

</div>

Hi,

I have a mysql in GCP to which I have already configured a sink to pubsub and from a VM with filebeat installed I am able to send the slow queries that reach me to the pubsub to elastic.

My problem is that the slow queries log comes line by line and I would like to group all the slow queries in a single document.

```auto
# Time: 2022-04-13T10:06:52.167264Z
# User@Host: service_db_usr[service_db_usr] @ [10.72.3.x] thread_id: 253176 server_id: 4054104550
# Query_time: 0.110813 Lock_time: 0.000063 Rows_sent: 189 Rows_examined: 391226
use mydatabase;
SET timestamp=1649844412;
select pipelinein0_.id as id1_24_, pipelinein0_.pipeline_definition_id as pipeline3_24_, pipelinein0_.state as state2_24_ from pipeline_instance pipelinein0_ where pipelinein0_.state='NOT_COMPLETED';

```

But if I do that, I wonder if I'll be able to do operations with them later, I mean eg. tell me the top10 of slowqueries. Because if I have all the lines in 1 single document will I be able to do that?

If yes, how could I group these lines into one? because unlike the examples I don't have a physical log and I don't have inputs, I only have the pubsub module configured in my filebeat.

- type: gcp-pubsub

Thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2022, 6:01pm UTC](https://discuss.elastic.co/t/how-parse-mysql-slow-queries-into-elastic/302364/2 "2022-05-11T18:01:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
