# Packetbeat capture only use query not others like select, insert, update

**URL:** <https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [September 20, 2018, 12:12pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287 "2018-09-20T12:12:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yecine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yecine/32/35711_2.png) [@Yecine](https://discuss.elastic.co/u/Yecine)\
**Post date:** [September 20, 2018, 12:12pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287/1 "2018-09-20T12:12:09Z")

</div>

I have configured packetbeat to monitor mysql and redirect that ELK

The issue that i have is that it only detect use query and no other query like selects or inserts updates i don''t understand why.

The port configured is correct and ssl is disable on mysql.

Can you help ?

Sometime in the logs i see stuff like ''mysql":{"unmatched\_responses":2141}'', not sure if its related or not

Thanks

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [September 21, 2018, 2:25pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287/2 "2018-09-21T14:25:53Z")

</div>

Hi Yecine,

Here are a few pointers, let me know if you've already checked all of those:

- Make sure you're not connecting locally via the socket 🙂 You'll want to ensure you're running your client or your library by connecting via either 127.0.0.1 or your remote address.
- When connecting over the network, you need to ensure Packetbeat is monitoring the correct network interface.
  - On Linux you can monitor them all with `packetbeat.interfaces.device: all`
  - On other OSes you will have to specify one network interface explicitly. If you're connecting locally, you'd have to configure something like this: `packetbeat.interfaces.device: lo0`. Check your interface IDs with `ifconfig` on Posix systems, or `ipconfig` on Windows.

If those don't help, can you give a few more details about your situation?

- Are you installing Packetbeat on the MySQL server directly, or trying to monitor traffic remotely?
- What version of MySQL and Packetbeat are you using?

The "unmatched\_responses" error would be expected when Packetbeat sees responses to queries it's unaware of (e.g. MySQL queries sent just before starting Packetbeat). Unless you're trying this on a high traffic server, I wouldn't expect it to reach 2000+ while you're starting up Packetbeat. We may need to dig deeper there.

---

<div class="post-metadata">

**Author:** ![Yecine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yecine/32/35711_2.png) [@Yecine](https://discuss.elastic.co/u/Yecine)\
**Post date:** [September 24, 2018, 4:08pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287/3 "2018-09-24T16:08:40Z")

</div>

Hello,

Web and database server are separated.

We have tried to put packet beat on both and i have the same result

We are connecting to the database throught it's ip so it's should be ok on this side.

We are on linuw so we have tried using device any and that didn't change anything

Here are the version of mysql and packetbeat :  
mysql Ver 14.14 Distrib 5.5.60  
packetbeat 6.4.1

Thanks for you help

---

<div class="post-metadata">

**Author:** ![Yecine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yecine/32/35711_2.png) [@Yecine](https://discuss.elastic.co/u/Yecine)\
**Post date:** [September 26, 2018, 9:42am UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287/4 "2018-09-26T09:42:03Z")

</div>

@webmat do you have an idea what is happening ?

Thanks

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [September 26, 2018, 7:04pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287/5 "2018-09-26T19:04:06Z")

</div>

Could you do/answer the following please:

- Which port is MySQL available on?
- Run `packetbeat devices` and post the results here
- Paste your packetbeat.yml config here. **Please make sure to remove any sensitive information first**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2018, 7:09pm UTC](https://discuss.elastic.co/t/packetbeat-capture-only-use-query-not-others-like-select-insert-update/149287/6 "2018-10-24T19:09:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
