# Mysql-Module Grok-Parsing Error

**URL:** <https://discuss.elastic.co/t/mysql-module-grok-parsing-error/125561>\
**Category:** Beats\
**Created:** [March 26, 2018, 8:12am UTC](https://discuss.elastic.co/t/mysql-module-grok-parsing-error/125561 "2018-03-26T08:12:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![strowi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strowi/32/29219_2.png) [@strowi](https://discuss.elastic.co/u/strowi)\
**Post date:** [March 26, 2018, 8:12am UTC](https://discuss.elastic.co/t/mysql-module-grok-parsing-error/125561/1 "2018-03-26T08:12:31Z")

</div>

Hi,

trying to get percona slow-logs into es with the mysql-module. But it seems there is some pattern mismatch?

- Version: 6.2.3
- Operating System: Ubuntu 16.04.3 LTS
- Steps to Reproduce:

```auto
filebeat.prospectors:

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

output.elasticsearch:
  hosts: ["es:30092"]
  index: "percona-%{[beat.version]}-%{+yyyy.MM.dd}"

setup:
  template:
    name: "percona-%{[beat.version]}"
    pattern: "percona-%{[beat.version]}-*"

filebeat.modules:
 - module: mysql
   # Error logs
   error:
     enabled: true
     var.paths: [/var/log/mysql/error.log]
   # Slow logs
   slowlog:
     enabled: true
     var.paths: [/var/log/mysql/mysql-slow.log]

```

error:

```auto
||Provided Grok expressions do not match field value: [# Time: 2018-03-26T08:03:59.598547Z]|

```

message:

```auto
@timestamp:
    March 26th 2018, 10:04:06.883
offset:
    6,594
beat.hostname:
    db03
beat.name:
    db03
beat.version:
    6.2.3
prospector.type:
    log
source:
    /var/log/mysql/mysql-slow.log
fileset.module:
    mysql
fileset.name:
    slowlog
fields.env:
    prod2
message:
    # User@Host: root[root] @ localhost [] Id: 37045034 # Schema: Last_errno: 0 Killed: 0 # Query_time: 10.000204 Lock_time: 0.000000 Rows_sent: 1 Rows_examined: 0 Rows_affected: 0 # Bytes_sent: 57 Tmp_tables: 0 Tmp_disk_tables: 0 Tmp_table_sizes: 0 # QC_Hit: No Full_scan: No Full_join: No Tmp_table: No Tmp_table_on_disk: No # Filesort: No Filesort_on_disk: No Merge_passes: 0 # No InnoDB statistics available for this query # Log_slow_rate_type: session Log_slow_rate_limit: 100 SET timestamp=1522051439; select sleep(10);
error.message:
    Provided Grok expressions do not match field value: [# User@Host: root[root] @ localhost [] Id: 37045034\n# Schema: Last_errno: 0 Killed: 0\n# Query_time: 10.000204 Lock_time: 0.000000 Rows_sent: 1 Rows_examined: 0 Rows_affected: 0\n# Bytes_sent: 57 Tmp_tables: 0 Tmp_disk_tables: 0 Tmp_table_sizes: 0\n# QC_Hit: No Full_scan: No Full_join: No Tmp_table: No Tmp_table_on_disk: No\n# Filesort: No Filesort_on_disk: No Merge_passes: 0\n# No InnoDB statistics available for this query\n# Log_slow_rate_type: session Log_slow_rate_limit: 100\nSET timestamp=1522051439;\nselect sleep(10);]
_id:
    Uv9WYWIBCQzjQvHMD8TZ
_type:
    doc
_index:
    percona-6.2.3-2018.03.26
_score:
    - 

```

original log:

```auto
# Time: 2018-03-26T08:03:59.598547Z
# User@Host: root[root] @ localhost [] Id: 37045034
# Schema: Last_errno: 0 Killed: 0
# Query_time: 10.000204 Lock_time: 0.000000 Rows_sent: 1 Rows_examined: 0 Rows_affected: 0
# Bytes_sent: 57 Tmp_tables: 0 Tmp_disk_tables: 0 Tmp_table_sizes: 0
# QC_Hit: No Full_scan: No Full_join: No Tmp_table: No Tmp_table_on_disk: No
# Filesort: No Filesort_on_disk: No Merge_passes: 0
# No InnoDB statistics available for this query
# Log_slow_rate_type: session Log_slow_rate_limit: 100
SET timestamp=1522051439;
select sleep(10);

```

regards,  
strowi

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [March 26, 2018, 4:44pm UTC](https://discuss.elastic.co/t/mysql-module-grok-parsing-error/125561/2 "2018-03-26T16:44:58Z")

</div>

It seems that percona server provides more information in slow logs, could you please create a [new issue](https://github.com/elastic/beats/issues/new) in Github to request support for your percona server version in the mysql module?

Thanks!

---

<div class="post-metadata">

**Author:** ![strowi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strowi/32/29219_2.png) [@strowi](https://discuss.elastic.co/u/strowi)\
**Post date:** [March 26, 2018, 5:07pm UTC](https://discuss.elastic.co/t/mysql-module-grok-parsing-error/125561/3 "2018-03-26T17:07:10Z")

</div>

Done: [https://github.com/elastic/beats/issues/6665](https://github.com/elastic/beats/issues/6665)

Thx!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2018, 7:07pm UTC](https://discuss.elastic.co/t/mysql-module-grok-parsing-error/125561/4 "2018-04-23T19:07:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
