Hi, I am Sorry, My English is not good, Please understand。
I use packetbeats as mysql Behavioral audit,Collect Architecture is packetbeats --> kafka --> logstash --> es --> kibana/grafana。
I has three problem.
- path fields not only display tablename.
- response fields display garbled.
- responsetime fileds display negative
Packetbeat client setting is
#============================== Network device ================================
packetbeat.interfaces.device: any
packetbeat.interfaces.type: af_packet
packetbeat.interfaces.snaplen: 65535
packetbeat.interfaces.buffer_size_mb: 100
packetbeat.flows:
enabled: false
#============================== Protocols ====================================
packetbeat.protocols:
-
type: icmp
enabled: false -
type: amqp
enabled: false -
type: cassandra
enabled: false -
type: dns
enabled: false -
type: http
enabled: false -
type: memcache
enabled: false -
type: mysql
enabled: true
ports: [3307]
send_request: false
send_response: true
max_rows: 40
max_row_length: 4096
transaction_timeout: 90s -
type: mysql
enabled: false
ports: [3306]
send_request: false
send_response: true
max_rows: 40
max_row_length: 4096
transaction_timeout: 30s -
type: pgsql
enabled: false -
type: redis
enabled: false -
type: thrift
enabled: false -
type: mongodb
enabled: false -
type: nfs
enabled: false
ports: [2049] -
type: tls
enabled: false
#=====================================================================
fields_under_root: true
max_procs: 1
processors:
- drop_fields:
fields: ["beat","proc","client_proc","release"]
#================================ Outputs ======================================
output.elasticsearch:
enabled: false
#----------------------------- Logstash output ---------------------------------
output.logstash:
enabled: false
#------------------------------- Kafka output ----------------------------------
output.kafka:
enabled: true
hosts: ["ip:port"]
topic: mysql-topic
worker: 4
max_retries: 3
max_message_bytes: 1200000
output.redis:
enabled: false
#----------------------------- Console output ---------------------------------
output.console:
enabled: false
pretty: true
#logging.level: error
logging.level: debug
#=====================#
packetbeats servier debug display