# Packetbeat parsing mongodb OP\_MSG

**URL:** <https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 25, 2021, 5:39am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535 "2021-10-25T05:39:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![chinaxushi](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Post date:** [October 25, 2021, 5:39am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/1 "2021-10-25T05:39:13Z")

</div>

Mongodb version 3.6 and later added 'OP'\_ MSG 'message type. When packet beat parses this type, the output field mongodb is empty. In addition, the most important thing is that there is no end time and no overall response time in the event output field  
Parsing output of type OP\_MSG:

```auto
  "mongodb": {},
  "resource": "",
  "event": {
    "start": "2021-10-23T08:28:16.778Z",
    "category": [
      "network_traffic",
      "network"
    ],
    "type": [
      "connection",
      "protocol"
    ],
    "kind": "event",
    "dataset": "mongodb"
  }

```

Parsing output of earlier types：

```auto
  "mongodb": {
    "fullCollectionName": "admin.$cmd",
    "numberToSkip": 0,
    "numberToReturn": 4294967295,
    "cursorId": 0,
    "startingFrom": 0,
    "numberReturned": 1
  },
  "resource": "admin.$cmd",
  "event": {
    "type": [
      "connection",
      "protocol"
    ],
    "kind": "event",
    "dataset": "mongodb",
    "duration": 139884,
    "start": "2021-07-27T08:27:27.473Z",
    "end": "2021-07-27T08:27:27.473Z",
    "category": [
      "network_traffic",
      "network"
    ]
  },

```

---

<div class="post-metadata">

**Author:** ![chinaxushi](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Post date:** [October 27, 2021, 6:07am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/2 "2021-10-27T06:07:56Z")

</div>

Can't anyone answer it? What is the problem with the configuration, or does packetbeat not support mongodb's new message format well.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 27, 2021, 7:24am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/3 "2021-10-27T07:24:56Z")

</div>

It doesn't look like this is supported - [Update MongoDB protocol with new opcodes · Issue #6191 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/6191)

---

<div class="post-metadata">

**Author:** ![chinaxushi](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Post date:** [October 27, 2021, 2:22pm UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/4 "2021-10-27T14:22:25Z")

</div>

Thank you for your reply.

I have seen many issues before. My understanding is that the version of 6. X at that time does not support OP\_MSG at all, and an error is reported directly in the background log. But now at least it can be resolved to be Op\_ MSG type message. Only some data is missing, and it is still key data.

Does this mean that the current version of packetbeat has limited support for new mongdb messages?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 27, 2021, 9:13pm UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/5 "2021-10-27T21:13:57Z")

</div>

It would appear so, yes.

---

<div class="post-metadata">

**Author:** ![chinaxushi](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Post date:** [October 28, 2021, 2:38am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/6 "2021-10-28T02:38:14Z")

</div>

Do you need to create an issues on GitHub?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 28, 2021, 2:38am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/7 "2021-10-28T02:38:59Z")

</div>

There's one above, definitely comment on it 🙂

---

<div class="post-metadata">

**Author:** ![chinaxushi](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Post date:** [October 28, 2021, 5:21am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/8 "2021-10-28T05:21:11Z")

</div>

Thank you. I have commented on

```auto
https://github.com/elastic/beats/issues/6191

```

---

<div class="post-metadata">

**Author:** ![chinaxushi](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@chinaxushi](https://discuss.elastic.co/u/chinaxushi)\
**Post date:** [November 2, 2021, 2:25am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/9 "2021-11-02T02:25:58Z")

</div>

GitHub did not respond after replying. Is it because issues has been closed?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2021, 4:26am UTC](https://discuss.elastic.co/t/packetbeat-parsing-mongodb-op-msg/287535/10 "2021-11-30T04:26:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
