# Mysql-Slow-Log

**URL:** <https://discuss.elastic.co/t/mysql-slow-log/41480>\
**Category:** Logstash\
**Created:** [February 11, 2016, 12:33pm UTC](https://discuss.elastic.co/t/mysql-slow-log/41480 "2016-02-11T12:33:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![novice](https://avatars.discourse-cdn.com/v4/letter/n/a87d85/32.png) [@novice](https://discuss.elastic.co/u/novice)\
**Post date:** [February 11, 2016, 12:33pm UTC](https://discuss.elastic.co/t/mysql-slow-log/41480/1 "2016-02-11T12:33:39Z")

</div>

Hi everyone,

I am using filebeats to forward mysql logs to logstash , and it breaks the query to different lines. I want the complete query as a single entry unlike a single line the way logstash does.  
What filter should be used ? I tried using multiline but didn't work.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 14, 2016, 2:47pm UTC](https://discuss.elastic.co/t/mysql-slow-log/41480/2 "2016-02-14T14:47:26Z")

</div>

A multiline filter or codec will work, but I strongly suggest that you use the newly introduced multiline feature in Filebeat. Joining lines that make up multiline messages should be done as close to the source as possible.

If you want more specific help you need to be more specific. What does the logs look like, what configuration have you tried, etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:11am UTC](https://discuss.elastic.co/t/mysql-slow-log/41480/3 "2017-07-06T05:11:37Z")

</div>


