# Packetbeats use mysql module, respontime display negative，path not only tablename

**URL:** https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327
**Category:** Beats
**Tags:** packetbeat
**Created:** [August 28, 2018, 11:21am UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327 "2018-08-28T11:21:19Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![test987654123](https://avatars.discourse-cdn.com/v4/letter/t/ecb155/32.png) [@test987654123](https://discuss.elastic.co/u/test987654123)
#### Post date: [August 28, 2018, 11:21am UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327/1 "2018-08-28T11:21:20Z")

</div>

Hi, I am Sorry, My English is not good， Please understand。

I use packetbeats as mysql Behavioral audit，Collect Architecture is packetbeats --\> kafka --\> logstash --\> es --\> kibana/grafana。

I has three problem.

1. path fields not only display tablename.
2. response fields display garbled.
3. responsetime fileds display negative

Packetbeat client setting is  
#============================== Network device ================================

packetbeat.interfaces.device: any  
packetbeat.interfaces.type: af\_packet  
packetbeat.interfaces.snaplen: 65535  
packetbeat.interfaces.buffer\_size\_mb: 100

packetbeat.flows:  
enabled: false

#============================== Protocols ====================================  
packetbeat.protocols:

- type: icmp  
enabled: false

- type: amqp  
enabled: false

- type: cassandra  
enabled: false

- type: dns  
enabled: false

- type: http  
enabled: false

- type: memcache  
enabled: false

- type: mysql  
enabled: true  
ports: [3307]  
send\_request: false  
send\_response: true  
max\_rows: 40  
max\_row\_length: 4096  
transaction\_timeout: 90s

- type: mysql  
enabled: false  
ports: [3306]  
send\_request: false  
send\_response: true  
max\_rows: 40  
max\_row\_length: 4096  
transaction\_timeout: 30s

- type: pgsql  
enabled: false

- type: redis  
enabled: false

- type: thrift  
enabled: false

- type: mongodb  
enabled: false

- type: nfs  
enabled: false  
ports: [2049]

- type: tls  
enabled: false

#=====================================================================  
fields\_under\_root: true  
max\_procs: 1

processors:

- drop\_fields:  
fields: ["beat","proc","client\_proc","release"]

#================================ Outputs ======================================  
output.elasticsearch:  
enabled: false

#----------------------------- Logstash output ---------------------------------  
output.logstash:  
enabled: false

#------------------------------- Kafka output ----------------------------------  
output.kafka:  
enabled: true  
hosts: ["ip:port"]  
topic: mysql-topic  
worker: 4  
max\_retries: 3  
max\_message\_bytes: 1200000

output.redis:  
enabled: false  
#----------------------------- Console output ---------------------------------  
output.console:  
enabled: false  
pretty: true  
#logging.level: error  
logging.level: debug  
#=====================#  
packetbeats servier debug display

 ![respontime](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9035a22dce28f03407562c37c8113882c789028.png)

 ![path_response_fields](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a8e56c9d650b6caed768ece240100a4e7a6f8b8.png)

---

<div class="post-metadata">

### Author: ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)
#### Post date: [August 29, 2018, 3:19pm UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327/2 "2018-08-29T15:19:24Z")

</div>

Thanks for your report. I'm not familiar with the mysql protocol, need some time to investigate what is going on. It looks like there's a problem with the response/request correlation.

Will open an issue to keep track of this.

Which version of packetbeat are you using? Although the mysql protocol hasn't changed recently.

Can you share a packet capture (pcap) that exposes this problems? Only if there's no sensitive data in it, of course.

To do so, run packetbeat with `--dump filename.pcap` and test it with `-t -I filename.pcap`.

Edit:  
Here's the issue I created

> <https://github.com/elastic/beats/issues/8139>

---

<div class="post-metadata">

### Author: ![test987654123](https://avatars.discourse-cdn.com/v4/letter/t/ecb155/32.png) [@test987654123](https://discuss.elastic.co/u/test987654123)
#### Post date: [September 18, 2018, 2:02am UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327/3 "2018-09-18T02:02:54Z")

</div>

Hi, I am sorry. Run packetbeat collect mysql aduit behavioral .

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f8b12caf9d66108e6c2f4668534b8fcdeecdf38.png)

---

<div class="post-metadata">

### Author: ![anzerchen](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@anzerchen](https://discuss.elastic.co/u/anzerchen)
#### Post date: [October 15, 2018, 7:06am UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327/4 "2018-10-15T07:06:28Z")

</div>

I had the same problem, My packetbeat version is 5.0.2, Do you fix it now?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 12, 2018, 7:09am UTC](https://discuss.elastic.co/t/packetbeats-use-mysql-module-respontime-display-negative-path-not-only-tablename/146327/5 "2018-11-12T07:09:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
