# Logstash and Mysql logs

**URL:** <https://discuss.elastic.co/t/logstash-and-mysql-logs/262374>\
**Category:** Elasticsearch\
**Created:** [January 27, 2021, 2:04pm UTC](https://discuss.elastic.co/t/logstash-and-mysql-logs/262374 "2021-01-27T14:04:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cwt](https://avatars.discourse-cdn.com/v4/letter/c/e47774/32.png) [@cwt](https://discuss.elastic.co/u/cwt)\
**Post date:** [January 27, 2021, 2:04pm UTC](https://discuss.elastic.co/t/logstash-and-mysql-logs/262374/1 "2021-01-27T14:04:41Z")

</div>

Hi. I have a problem with a JSON logs from mysql servers. I send such logs to logstash but they don't get into elastic and give no error. If I change single quotes for **'alerts test'** to double quotes **"alerts test"** everything is ok. But how to make single quotes parse correctly or track down the error?

```auto
{
  "audit_record": {
    "name": "Query",
    "record": "467509661_2020-07-24T06:56:21",
    "timestamp": "2021-01-12T15:29:35 UTC",
    "command_class": "select",
    "connection_id": "23043788",
    "status": 0,
    "sqltext": "SELECT 'alerts test' FROM tests.tests LIMIT 2",
    "user": "test[test] @ [192.168.2.18]",
    "host": "",
    "os_user": "",
    "ip": "192.168.2.18",
    "db": ""
  },
  "HOST": "test",
  "UNIXTIME": 1610465376
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2021, 2:04pm UTC](https://discuss.elastic.co/t/logstash-and-mysql-logs/262374/2 "2021-02-24T14:04:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
