# Unable to get mysql performance in packetbeat

**URL:** <https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [May 28, 2015, 9:17am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450 "2015-05-28T09:17:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 9:17am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/1 "2015-05-28T09:17:07Z")

</div>

Im not getting the mysql performance in packetbeat. I'm getting http requests in packetbeat. I have done the tracing by "packetbeat -e -dump trace.pcap"... but the output for that command is nothing. I didnt get anything. Please help me to get the mysql performance

Im using ubuntu and mysql with port 3306. Im using kibana4 as dashboard.  
Http performance: i'm able to get  
 ![](https://sea2.discourse-cdn.com/elastic/uploads/default/original/4/c/4c4934fc5aa0326076f9314c48c2bb7113cb0f8d.jpg)

Mysql performance: I'm not getting anything  
 ![](https://sea2.discourse-cdn.com/elastic/uploads/default/original/7/1/7152461f82947c9e2d2ae55c08aa6e47c84fefe0.jpg)

This is my conf file:

![](https://sea2.discourse-cdn.com/elastic/uploads/default/original/6/7/67429181f6b807601fce58895c03080c110f506b.jpg)

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 9:23am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/2 "2015-05-28T09:23:41Z")

</div>

Thanks for the details. Just to confirm, you are using Paketbeat version 1.0.0~Beta1, right? You need to leave the `packetbeat -e -dump trace.pcap` running for a bit so that it captures some traffic. Is the `trace.pcap` file empty?

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 9:29am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/3 "2015-05-28T09:29:14Z")

</div>

Yes i'm using Paketbeat version 1.0.0~Beta1.. I'm not getting anything if im running that command.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 9:30am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/4 "2015-05-28T09:30:53Z")

</div>

Ok, to confirm that traffic is flowing on port 3306, can you try doing the same trace with tcpdump? The syntax should be:

```
tcpdump -s0 -w trace.pcap "port 3306"

```

If that works, then please send us the pcap file.

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 9:32am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/5 "2015-05-28T09:32:55Z")

</div>

i'm getting this output :

tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes

Can you tell me where will be the pcap file?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 9:34am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/6 "2015-05-28T09:34:15Z")

</div>

Ok, just keep it running for a minute or two, stop it with ^C and than see if it created `trace.pcap`.

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 9:37am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/7 "2015-05-28T09:37:50Z")

</div>

this is the output if i do ^C :

2 packets received by filter  
0 packets dropped by kernel

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 9:40am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/8 "2015-05-28T09:40:16Z")

</div>

Hmm, only 2 packets. That seems a bit low. What about `trace.pcap`, was it created? If yes, please send it to us. (If you cannot upload it here, please email it to [tudor@elastic.co](mailto:tudor@elastic.co)).

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 9:42am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/9 "2015-05-28T09:42:53Z")

</div>

Where will be that file trace.pcap .. when i stop that, i didn't see any file was created with that name.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 9:46am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/10 "2015-05-28T09:46:19Z")

</div>

Should have been in your current working directory. That's strange, tcpdump should have at least created an empty (24 bytes long actually) file.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 9:52am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/11 "2015-05-28T09:52:10Z")

</div>

If you cannot find it, lets try this test:

- In one terminal tab, start tcpdump and and leave it running:

- On another terminal tab, start the mysql prompt replacing root with a user you have for mysql:

- On the mysql prompt to a simple select like:

- Stop tcpdump and check that the `trace.pcap` file was created.

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 9:55am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/13 "2015-05-28T09:55:22Z")

</div>

After doing this also i sent you another trace.pacp file to your id.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 10:00am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/14 "2015-05-28T10:00:11Z")

</div>

Ok, first file was empty, second one contain the `select 1` as expected.

Just for completeness you can do the same, but instead of tcpdump you can use packetbeat like this:

```
packetbeat -e -d "publish" -N

```

It should print a JSON object for that select.

What I suspect is going on is that your application connects to MySQL via the unix sockets rather than the network. The way to force it using the network is usually to tell it to connect to `127.0.0.1` rather than `localhost`. What programming lagnuage / stack are you having?

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 10:03am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/15 "2015-05-28T10:03:19Z")

</div>

This is the output for that command:

publish.go:221: INFO Dry run mode. All output types except the file based one are disabled.  
geolite.go:61: INFO Loaded GeoIP data from: /usr/share/GeoIP/GeoIP.dat  
publish.go:267: INFO No shipper name configured, using hostname 'ip-10-150-147-210'  
procs.go:88: INFO Process matching enabled

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 10:07am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/16 "2015-05-28T10:07:23Z")

</div>

Hmm, did you do the select while packetbeat was running? The trace you sent definitely works on my computer.

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 10:14am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/17 "2015-05-28T10:14:46Z")

</div>

In one terminal im running this command :  
packetbeat -e -d "publish" -N  
In one terminal i started mysql and done select query..  
when i did this.. i got output in other terminal where im running the 1st command but i'm not getting anything on dashboard.  
.  
 ![](https://sea2.discourse-cdn.com/elastic/uploads/default/original/0/0/003fad62a443515be485104b8e0e5cd275d94206.jpg)  
This is the output where im running the first command:  
 ![](https://sea2.discourse-cdn.com/elastic/uploads/default/original/1/1/110fa64c3445a07ab064ddc355ad0365838079ef.jpg)

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 10:20am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/18 "2015-05-28T10:20:23Z")

</div>

Im getting this as shown in above screenshot:  
mysql.go:563: WARN Response from unknown transaction. Ignoring.

I'm not getting anything on dashboard.  
 ![](https://sea2.discourse-cdn.com/elastic/uploads/default/original/7/2/72cf025676e881260d92cbdd3dbc979c5ba01a3a.jpg)

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 28, 2015, 11:33am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/19 "2015-05-28T11:33:37Z")

</div>

I'm getting everything what im doing in mysql to elasticsearch. But im unable to get it in dashboard.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 28, 2015, 11:35am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/20 "2015-05-28T11:35:17Z")

</div>

Ok, cool, so it works fine when using the mysql client. If you remove the -N, i.e. `packetbeat -e -d "publish"`, it should also insert into Elasticsearch so you will see the transactions in Kibana.

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [May 29, 2015, 11:03am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/21 "2015-05-29T11:03:03Z")

</div>

Thanq very much for the support Tudor... Now everything is working fine and visualization is excellent.

[Next page](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450.md?page=2)
