# Mssql all requests

**URL:** <https://discuss.elastic.co/t/mssql-all-requests/279648>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 26, 2021, 3:14pm UTC](https://discuss.elastic.co/t/mssql-all-requests/279648 "2021-07-26T15:14:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergey\_Zaguba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergey_zaguba/32/80579_2.png) [@Sergey\_Zaguba](https://discuss.elastic.co/u/Sergey_Zaguba)\
**Post date:** [July 26, 2021, 3:14pm UTC](https://discuss.elastic.co/t/mssql-all-requests/279648/1 "2021-07-26T15:14:36Z")

</div>

I have a Windows server with MsSQL + filebeat. I want to see in ELK all requests that are sent to all databases. Please tell me how best to do this. I have activated the mssql module in filebeat, but I still only get the windows system logs and not mssql. Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2021, 11:07pm UTC](https://discuss.elastic.co/t/mssql-all-requests/279648/2 "2021-07-26T23:07:17Z")

</div>

Welcome to our community! 😃

From [the docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-mssql.html) of that module;

> The mssql module parses error logs created by MSSQL.

I don't know any other way to do what you want though sorry.

---

<div class="post-metadata">

**Author:** ![eMitch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emitch/32/93607_2.png) [@eMitch](https://discuss.elastic.co/u/eMitch)\
**Post date:** [July 26, 2021, 11:41pm UTC](https://discuss.elastic.co/t/mssql-all-requests/279648/3 "2021-07-26T23:41:38Z")

</div>

There are ways through mssql to get requests such as DMVs and Extended Events.  
For example, you can use Logstash with the JDBC input plugin to query the MSSQL DMVs to get query history and many other statistics which you can then ingest into Elastic.  
Much of this answer will depend on your version and what details your after regarding the queries.

Generally though, trying to capture ALL requests is not something you want to do in a production environment due to the overhead of the capture.  
Going after the DMVs on a schedule will be much less overhead than something like profiler.

Another option is to put something in the middle such as HAProxy to forward the TCP requests to mssql. HAProxy will log all requests and there are many ways to pull them out into Beats or Logstash in order to ingest them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2021, 1:41am UTC](https://discuss.elastic.co/t/mssql-all-requests/279648/4 "2021-08-24T01:41:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
