Hi, I am Sorry, My English is not good, Please understand。
I use packetbeats as mysql Behavioral audit,Collect Architecture is packetbeats --> kafka --> logstash --> es --> kibana/grafana。
I has three problem.
- path fields not only display tablename.
- response fields display garbled.
- responsetime fileds display negative
Packetbeat client setting is
#============================== Network device ================================
packetbeat.interfaces.device: any
packetbeat.interfaces.type: af_packet
packetbeat.interfaces.snaplen: 65535
packetbeat.interfaces.buffer_size_mb: 100
packetbeat.flows:
enabled: false
#============================== Protocols ====================================
packetbeat.protocols:
- 
type: icmp 
 enabled: false
- 
type: amqp 
 enabled: false
- 
type: cassandra 
 enabled: false
- 
type: dns 
 enabled: false
- 
type: http 
 enabled: false
- 
type: memcache 
 enabled: false
- 
type: mysql 
 enabled: true
 ports: [3307]
 send_request: false
 send_response: true
 max_rows: 40
 max_row_length: 4096
 transaction_timeout: 90s
- 
type: mysql 
 enabled: false
 ports: [3306]
 send_request: false
 send_response: true
 max_rows: 40
 max_row_length: 4096
 transaction_timeout: 30s
- 
type: pgsql 
 enabled: false
- 
type: redis 
 enabled: false
- 
type: thrift 
 enabled: false
- 
type: mongodb 
 enabled: false
- 
type: nfs 
 enabled: false
 ports: [2049]
- 
type: tls 
 enabled: false
#=====================================================================
fields_under_root: true
max_procs: 1
processors:
- drop_fields:
 fields: ["beat","proc","client_proc","release"]
#================================ Outputs ======================================
output.elasticsearch:
enabled: false
#----------------------------- Logstash output ---------------------------------
output.logstash:
enabled: false
#------------------------------- Kafka output ----------------------------------
output.kafka:
enabled: true
hosts: ["ip:port"]
topic: mysql-topic
worker: 4
max_retries: 3
max_message_bytes: 1200000
output.redis:
enabled: false
#----------------------------- Console output ---------------------------------
output.console:
enabled: false
pretty: true
#logging.level: error
logging.level: debug
#=====================#
packetbeats servier debug display


