# Mysql slow log cannot parse

**URL:** <https://discuss.elastic.co/t/mysql-slow-log-cannot-parse/128170>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 16, 2018, 11:04am UTC](https://discuss.elastic.co/t/mysql-slow-log-cannot-parse/128170 "2018-04-16T11:04:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zeroliuhuang](https://avatars.discourse-cdn.com/v4/letter/z/94ad74/32.png) [@zeroliuhuang](https://discuss.elastic.co/u/zeroliuhuang)\
**Post date:** [April 16, 2018, 11:04am UTC](https://discuss.elastic.co/t/mysql-slow-log-cannot-parse/128170/1 "2018-04-16T11:04:22Z")

</div>

filebeat version is 6.2.3  
mysql version is 5.6.38

I install filebeat filebeat-6.2.3-linux-x86\_64.tar.gz. and start mysql modules.  
when I start filebeat with mysql 5.1.73 and parse mysql slow log , it can parse the slow log success. but when I start filebeat with mysql 5.6.38 , it cannot parse mysql slow log ,the error is:

```auto
Provided Grok expressions do not match field value: .....

```

and when I execute a SQL in mysql , it will split two message and send to elasticseach. the SQL is "select sleep(2);". filebeat will send '\n# Time: [0-9]+ [0-9][0-9]:[0-9][0-9]:[0-9]0-9?$' to elasticsearch.

so what should I do ? change the mysql slow pipeline.json ?

---

<div class="post-metadata">

**Author:** ![zeroliuhuang](https://avatars.discourse-cdn.com/v4/letter/z/94ad74/32.png) [@zeroliuhuang](https://discuss.elastic.co/u/zeroliuhuang)\
**Post date:** [April 17, 2018, 2:47am UTC](https://discuss.elastic.co/t/mysql-slow-log-cannot-parse/128170/2 "2018-04-17T02:47:46Z")

</div>

I have change the config/slowlog.yml file .

```auto
exclude_lines: ['^[\/\w\.]+, Version: .* started with:.*','^# Time.*'] # Exclude the header

```

and the slow log can parse success and cannot see the error in kibana

```auto
Provided Grok expressions do not match field value: .....

```

and I also chane the pipeline.json file.  
before change:

```auto
"^# User@Host: %{USER:mysql.slowlog.user}(\\[[^\\]]+\\])? @ %{HOSTNAME:mysql.slowlog.host} \\[(%{IP:mysql.slowlog.ip})?\\](\\s*Id:\\s* %{NUMBER:mysql.slowlog.id})?\n# Query_time: %{NUMBER:mysql.slowlog.query_time.sec}\\s* Lock_time: %{NUMBER:mysql.slowlog.lock_time.sec}\\s* Rows_sent: %{NUMBER:mysql.slowlog.rows_sent}\\s* Rows_examined: %{NUMBER:mysql.slowlog.rows_examined}\n(SET timestamp=%{NUMBER:mysql.slowlog.timestamp};\n)?%{GREEDYMULTILINE:mysql.slowlog.query}"

```

alter change:

```auto
"^# User@Host: %{USER:mysql.slowlog.user}(\\[[^\\]]+\\])? @ %{HOSTNAME:mysql.slowlog.host} \\[(IP:mysql.slowlog.ip)?\\](\\s*Id:\\s* %{NUMBER:mysql.slowlog.id})?\n# Query_time: %{NUMBER:mysql.slowlog.query_time.sec}\\s* Lock_time: %{NUMBER:mysql.slowlog.lock_time.sec}\\s* Rows_sent: %{NUMBER:mysql.slowlog.rows_sent}\\s* Rows_examined: %{NUMBER:mysql.slowlog.rows_examined}\n(SET timestamp=%{NUMBER:mysql.slowlog.timestamp};\n)?%{GREEDYMULTILINE:mysql.slowlog.query}"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2018, 2:47am UTC](https://discuss.elastic.co/t/mysql-slow-log-cannot-parse/128170/3 "2018-05-15T02:47:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
