# Packetbeat & MySQL

**URL:** <https://discuss.elastic.co/t/packetbeat-mysql/54042>\
**Category:** Beats\
**Created:** [June 27, 2016, 1:08pm UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042 "2016-06-27T13:08:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_Csuka](https://avatars.discourse-cdn.com/v4/letter/k/7feea3/32.png) [@Kevin\_Csuka](https://discuss.elastic.co/u/Kevin_Csuka)\
**Post date:** [June 27, 2016, 1:08pm UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/1 "2016-06-27T13:08:41Z")

</div>

Hi,

I'm running an Ubuntu 14.04 machine in Vagrant / Virtualbox, i spinned up a scotchbox, acting as a LAMP server.  
Packetbeat 1.2.3 is sending data directly to Elasticsearch.  
Elasticsearch is successfully receiving data from the server. So connection-wise everything is good. The bind-address of MySQL is set to 127.0.0.1

Data is inserted into a MySQL database named 'test1' via a php script. But this traffic is not shown in Kibana.  
How can I view the impact of the performance in Kibana of that data being inserted?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 27, 2016, 1:19pm UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/2 "2016-06-27T13:19:56Z")

</div>

1. with virtual machines always check time being in sync.
2. have you tried plain `mysql` command line tool (make sure you connect via tcp, not unix socket) and do a `SELECT 1;` ?
3. is your script using prepared-statements? These are [currently not supported by the protocol analyzer](https://github.com/elastic/beats/issues/683).

---

<div class="post-metadata">

**Author:** ![Kevin\_Csuka](https://avatars.discourse-cdn.com/v4/letter/k/7feea3/32.png) [@Kevin\_Csuka](https://discuss.elastic.co/u/Kevin_Csuka)\
**Post date:** [June 28, 2016, 8:07am UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/3 "2016-06-28T08:07:44Z")

</div>

> [@steffens](#):
>
> 1. with virtual machines always check time being in sync.

Check, time is indeed correct.

> [@steffens](#):
>
> 2.have you tried plain mysql command line tool (make sure you connect via tcp, not unix socket) and do a SELECT 1; ?

Works.

```auto
mysql -h 127.0.0.1 -u root -p 
```

See this image: [Imgur: The magic of the Internet](http://imgur.com/r7NQcJD)

> [@steffens](#):
>
> 3.Is your script using prepared-statements? These are currently not supported by the protocol analyzer

It's a very, very simple php code that POST"s three variables into the Database. For convience:

[code]$first\_name = mysqli\_real\_escape\_string($link, $\_POST['firstname']);  
$last\_name = mysqli\_real\_escape\_string($link, $\_POST['lastname']);  
$email\_address = mysqli\_real\_escape\_string($link, $\_POST['email']);

$sql = "INSERT INTO persons (first\_name, last\_name, email\_address) VALUES ('$first\_name', '$last\_name', '$email\_address')";  
echo "Records added successfully.";  
} [/code]

So three variables are posted into the database. Should packetbeat send the metrics of the performance to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 28, 2016, 8:20am UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/4 "2016-06-28T08:20:25Z")

</div>

Is php script connecting to database via unix socket?

---

<div class="post-metadata">

**Author:** ![Kevin\_Csuka](https://avatars.discourse-cdn.com/v4/letter/k/7feea3/32.png) [@Kevin\_Csuka](https://discuss.elastic.co/u/Kevin_Csuka)\
**Post date:** [June 28, 2016, 8:22am UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/5 "2016-06-28T08:22:44Z")

</div>

I'm guessing it is...

```auto
mysqli_connect("127.0.0.1", "root", "steffens", "scotchbox");
 
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 28, 2016, 8:26am UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/6 "2016-06-28T08:26:30Z")

</div>

have you checked with netstat? Have you tried to capture a raw trace using tcpdump and check in wireshark traffic is send unencrypted on interface being monitored?

---

<div class="post-metadata">

**Author:** ![Kevin\_Csuka](https://avatars.discourse-cdn.com/v4/letter/k/7feea3/32.png) [@Kevin\_Csuka](https://discuss.elastic.co/u/Kevin_Csuka)\
**Post date:** [June 28, 2016, 8:46am UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/7 "2016-06-28T08:46:23Z")

</div>

> [@steffens](#):
>
> ireshark traffic is send unencrypted on interface being monit

While inserting data into the database I performed

```auto
 packetbeat -e -dump trace.pcap 
```

I have no idea why, but the data is now shown in Kibana...  
Thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2016, 1:09pm UTC](https://discuss.elastic.co/t/packetbeat-mysql/54042/8 "2016-07-18T13:09:04Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
