# Packetbeat unable to monitor mysql traffic

**URL:** <https://discuss.elastic.co/t/packetbeat-unable-to-monitor-mysql-traffic/321690>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [December 20, 2022, 8:40pm UTC](https://discuss.elastic.co/t/packetbeat-unable-to-monitor-mysql-traffic/321690 "2022-12-20T20:40:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [December 20, 2022, 8:40pm UTC](https://discuss.elastic.co/t/packetbeat-unable-to-monitor-mysql-traffic/321690/1 "2022-12-20T20:40:13Z")

</div>

I'm trying out packetbeat to monitor events for the mysql protocol. Packetbeat seems to be able to detect packets on `destination.port: 3306` which is the default mysql port as shown in this screenshot here:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6983bb12f3197cdd9d4666537628fcfc14c2a2c.jpeg)

But packetbeat gives zero results for `network.protocol: mysql or type: mysql`, as shown here:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d60c761274aa6ce6d244dc1950aca158b2507a8.jpeg)

And this is why the default MySQL dashboards show no results, as shown here:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f6db3ff1c32c5ac06d350d8f40e47697e3cac06f.jpeg)

My current setup is:

- Elastic and Kibana version 8.5 are installed on the same server somewhere in North America (170.187.192.170)
- Packetbeat version 8.5 and MySQL server version 8 are installed on the same server somewhere in Australia (194.195.121.47)
- My MySQL client is installed on a server somewhere in Canada (172.105.5.73) , and I use the client to do a `SELECT * FROM table` once it connects to the server in Australia

This is my `/etc/packetbeat/packetbeat.yml`

```auto
packetbeat.interfaces.device: any
packetbeat.interfaces.poll_default_route: 1m
packetbeat.interfaces.internal_networks:
  - private
packetbeat.flows:
  timeout: 30s
  period: 10s
packetbeat.protocols:
- type: icmp
  enabled: true
- type: amqp
  ports: [5672]
- type: dhcpv4
  ports: [67, 68]
- type: dns
  ports: [53]
- type: http
  ports: [80, 8080, 8000, 5000, 8002]
- type: mysql
  ports: [3306,3307]
  send_request: true
  send_response: true
  enabled: true
- type: tls
  ports: [443]
- type: sip
  ports: [5060]
setup.template.settings:
  index.number_of_shards: 1
setup.dashboards.enabled: true
setup.kibana:
  host: "https://kibana.example.net:5601"
output.elasticsearch:
  hosts: ["elastic.example.net:9200"]
  protocol: "https"
  api_key: "${ES_API_KEY}"
  pipeline: geoip-info
processors:
  - # Add forwarded to tags when processing data from a network tap or mirror.
    if.contains.tags: forwarded
    then:
      - drop_fields:
          fields: [host]
    else:
      - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - detect_mime_type:
      field: http.request.body.content
      target: http.request.mime_type
  - detect_mime_type:
      field: http.response.body.content
      target: http.response.mime_type

```

There are no firewalls in involved. There is no port forwarding or traffic redirection involved. No VPNs were used.

How do I get packetbeat to monitor mysql traffic?

* * *

To install mysql, all I did was `apt-get install mysql-server` and then I used this for `/etc/mysql/mysql.conf.d/mysql.conf`

```auto
[mysqld]
user = mysql
bind-address = 0.0.0.0
mysqlx-bind-address = 0.0.0.0
key_buffer_size = 16M
myisam-recover-options = BACKUP
log_error = /var/log/mysql/error.log
max_binlog_size = 100M

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2023, 10:40pm UTC](https://discuss.elastic.co/t/packetbeat-unable-to-monitor-mysql-traffic/321690/2 "2023-01-17T22:40:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
