As the title,
Among them, the end time is earlier than the start time, and event.duration cannot be captured. and path fetches incorrectly
Publish event is as follows
2021-04-28T14:53:43.296+0800 DEBUG [processors] processing/processors.go:203 Publish event: {
"@timestamp": "2021-04-28T06:53:43.294Z",
"@metadata": {
"beat": "packetbeat",
"type": "_doc",
"version": "7.12.0"
},
"network": {
"type": "ipv4",
"transport": "tcp",
"protocol": "mysql",
"direction": "ingress",
"community_id": "1:ySbtBEgtF54EBNkEeeSA7ZUkyD4=",
"bytes": 4196
},
"mysql": {
"insert_id": 0,
"num_rows": 11,
"num_fields": 13,
"affected_rows": 0
},
"destination": {
"ip": "10.23.23.226",
"port": 3306,
"bytes": 3986
},
"query": "select\n \n id, external_userid, family_id, unionid, create_time, update_time , parent_id,bind_source,bind_project,operator_staff_id\n \n from wx_work_student_contact\n where family_id = 16022072",
"path": "vk_wechat.wx_work_staff_contact_tag, 上周未完成作业督学.04-03 09:30SLAC-L4-U3-LC1-2, 上周未完成作业督学.04-10 09:30SLAC-L4-U3-LC1-3, 上周未完成作业督学.04-24 09:30SLAC-L4-U4-LC1-2, 个人标签.2.6日4级别外教周一, 课后作业督学.03-27 09:30SLAC-L4-U3-LC1-1, 课后作业督学.04-03 09:30SLAC-L4-U3-LC1-2, 课后作业督学.04-10 09:30SLAC-L4-U3-LC1-3, 课后作业督学.04-17 09:30SLAC-L4-U4-LC1-1, 课后作业督学.04-24 09:30SLAC-L4-U4-LC1-2",
"type": "mysql",
"source": {
"ip": "10.245.67.95",
"port": 28184,
"bytes": 210
},
"status": "OK",
"related": {
"ip": [
"10.245.67.95",
"10.23.23.226"
]
},
"agent": {
"id": "01957399-2f83-4cb5-8765-f9704ad14785",
"name": "l-lp-im-mysql0.lp.prod.ali.dm",
"type": "packetbeat",
"version": "7.12.0",
"hostname": "l-lp-im-mysql0.lp.prod.ali.dm",
"ephemeral_id": "de072258-737f-41f4-bd23-de9ddc96e4a9"
},
"host": {
"name": "l-lp-im-mysql0.lp.prod.ali.dm",
"hostname": "l-lp-im-mysql0.lp.prod.ali.dm",
"architecture": "x86_64",
"os": {
"kernel": "2.6.32-642.13.1.el6.x86_64",
"codename": "Final",
"type": "linux",
"platform": "centos",
"version": "6.8 (Final)",
"family": "redhat",
"name": "CentOS"
},
"containerized": false,
"ip": [
"10.23.23.226"
],
"mac": [
"00:16:3e:0e:3b:b7"
]
},
"ecs": {
"version": "1.8.0"
},
"method": "SELECT",
"event": {
"type": [
"connection",
"protocol"
],
"kind": "event",
"dataset": "mysql",
"start": "2021-04-28T06:53:43.294Z",
"end": "2021-04-28T06:53:43.187Z",
"category": [
"network_traffic",
"network"
]
},
"client": {
"ip": "10.245.67.95",
"port": 28184,
"bytes": 210
},
"server": {
"ip": "10.23.23.226",
"port": 3306,
"bytes": 3986
}
}