# Packetbeat is not monitoring any network traffic!

**URL:** <https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403>\
**Category:** Beats\
**Created:** [August 9, 2017, 8:59am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403 "2017-08-09T08:59:19Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![DharaniKumar](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@DharaniKumar](https://discuss.elastic.co/u/DharaniKumar)\
**Post date:** [August 9, 2017, 8:59am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/1 "2017-08-09T08:59:19Z")

</div>

Hi,  
i'm using packetbeat 5.5.0 in my ubuntu machine. For test sake i commented out all the protocols except mysql(in my old app server), as i wanted to monitor mysql traffic in kibana. But i don't know whats the issue around this. Strange thing is when i used another app server which in that i didn't installed a mysql server, but in that it shows mysql protocol traffic. Any kind of help is welcome.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![DharaniKumar](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@DharaniKumar](https://discuss.elastic.co/u/DharaniKumar)\
**Post date:** [August 9, 2017, 10:36am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/2 "2017-08-09T10:36:48Z")

</div>

Even when i did insert or delete datas from my table those actions where not monitored in packetbeat

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 9, 2017, 10:29pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/3 "2017-08-09T22:29:55Z")

</div>

Here are some things to check:

1. Make sure you have packetbeat sniffing on the correct interface. Probably you have `any` configured since you are on Linux.
2. Make sure you have it monitoring the correct mysql port you are using.
3. Make sure you have traffic going to mysql _over the network_ and not through a unix socket like `/var/lib/mysql/mysql.sock`.

---

<div class="post-metadata">

**Author:** ![DharaniKumar](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@DharaniKumar](https://discuss.elastic.co/u/DharaniKumar)\
**Post date:** [August 10, 2017, 11:38am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/4 "2017-08-10T11:38:46Z")

</div>

There is no file name like mysql.sock in the directory you've mentioned @andrewkroh

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 10, 2017, 1:02pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/5 "2017-08-10T13:02:03Z")

</div>

The location of the socket may be different (and it doesn't really matter). Just ensure that whatever method you use to communicate with the server is over TCP and not a unix socket. If you are using the `mysql` CLI tool there are parameters you can pass to ensure it uses TCP. See [Connecting to the MySQL Server](https://dev.mysql.com/doc/refman/5.5/en/connecting.html).

---

<div class="post-metadata">

**Author:** ![DharaniKumar](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@DharaniKumar](https://discuss.elastic.co/u/DharaniKumar)\
**Post date:** [August 10, 2017, 1:21pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/6 "2017-08-10T13:21:10Z")

</div>

We aren't using any mysql client @andrewkroh. It seems, mysql is running on TCP/IP on 3306 port in my ubuntu server.

root@sappserver:~# netstat -tulpn  
Active Internet connections (only servers)  
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name  
tcp 0 0 127.0.0.1:3306 0.0.0.0:\* LISTEN 1703/mysqld  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN 1487/sshd  
tcp6 0 0 :::80 :::\* LISTEN 3062/apache2  
tcp6 0 0 :::22 :::\* LISTEN 1487/sshd

Any help?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 10, 2017, 2:02pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/7 "2017-08-10T14:02:52Z")

</div>

Is the traffic to mysql encrypted? Packetbeat won't be able to monitor the traffic if it is. What is the client? How is it configured?

You can also try to enable debug in Packetbeat (`logging.level: debug` in your config file) so see if this provides any clues.

---

<div class="post-metadata">

**Author:** ![DharaniKumar](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@DharaniKumar](https://discuss.elastic.co/u/DharaniKumar)\
**Post date:** [August 11, 2017, 5:32am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/8 "2017-08-11T05:32:48Z")

</div>

I've mysql server installed in my ubuntu machine. I didnt installed any mysql client in my ubuntu.

So we need to install both mysql server and client in the same machine to monitor mysql traffic through packetbeat?

Also tell me some steps to how to find whether my mysql traffic is encrypted or not.

Thank You.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 11, 2017, 5:52pm UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/9 "2017-08-11T17:52:36Z")

</div>

> [@DharaniKumar](#):
>
> So we need to install both mysql server and client in the same machine to monitor mysql traffic through packetbeat?

The client can be on a different host.

> [@DharaniKumar](#):
>
> Also tell me some steps to how to find whether my mysql traffic is encrypted or not.

I think newer versions use SSL by default. You'll have to check the mysql docs. You can disable SSL on either the [client-side](https://dev.mysql.com/doc/refman/5.7/en/using-secure-connections.html) or on the [server](https://serverfault.com/questions/770618/how-to-disable-ssl-plugin-on-mysql-5-7-server#770619).

---

<div class="post-metadata">

**Author:** ![DharaniKumar](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@DharaniKumar](https://discuss.elastic.co/u/DharaniKumar)\
**Post date:** [August 12, 2017, 4:08am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/10 "2017-08-12T04:08:22Z")

</div>

Thanks for your help @andrewkroh i got the problem solved.  
The issue is we didnt published packetbeat to monitor mysql traffic.  
sudo ./packetbeat -configtest -e -c /etc/packetbeat/packetbeat.yml is what i used in my terminal and opened another terminal for using mysql operations.  
When i used mysql commands it showed the mysql traffic.  
Anyways thanks for time and help @andrewkroh it will be used for someothers with the same issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2017, 8:59am UTC](https://discuss.elastic.co/t/packetbeat-is-not-monitoring-any-network-traffic/96403/11 "2017-08-30T08:59:36Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
