# Unable to get mysql stats using packet beats

**URL:** https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719
**Category:** Beats
**Tags:** packetbeat
**Created:** [September 21, 2015, 4:16pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719 "2015-09-21T16:16:36Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![tarunsapra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarunsapra/32/3903_2.png) [@tarunsapra](https://discuss.elastic.co/u/tarunsapra)
#### Post date: [September 21, 2015, 4:16pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/1 "2015-09-21T16:16:36Z")

</div>

I can't seem to get packet beat shipper to send mysql stats to ES.

I went through this thread - [Unable to get mysql performance in packetbeat](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450)

and tried the following steps [Unable to get mysql performance in packetbeat](https://discuss.elastic.co/t/unable-to-get-mysql-performance-in-packetbeat/1450/11)

but the file generated trace.pcap is empty when i open with wireshark. I am using mac os x (yosemite) and packetbeat-1.0.0-beta3-darwin.

Also, I logged into mysql using 127.0.0.1 in order to use the port and avoid the socket issue.

Traffic is flowing on the port 3306 as well.  
\> tcpdump -s0 -w trace.pcap "port 3306"  
\> tcpdump: data link type PKTAP  
\> tcpdump: listening on pktap, link-type PKTAP (Packet Tap), capture size 65535 bytes

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [September 21, 2015, 4:54pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/2 "2015-09-21T16:54:38Z")

</div>

Just to make sure I understand it correctly, when you run:

```
tcpdump -s0 -w trace.pcap "port 3306"

```

do you get an empty trace.pcap?

---

<div class="post-metadata">

### Author: ![tarunsapra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarunsapra/32/3903_2.png) [@tarunsapra](https://discuss.elastic.co/u/tarunsapra)
#### Post date: [September 21, 2015, 6:42pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/3 "2015-09-21T18:42:57Z")

</div>

Hi @monica,

I get on my terminal screen -

tcpdump: data link type PKTAP  
tcpdump: listening on pktap, link-type PKTAP (Packet Tap), capture size 65535 bytes  
^C0 packets captured  
223 packets received by filter

and yes the file is empty

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [September 21, 2015, 8:13pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/4 "2015-09-21T20:13:45Z")

</div>

Hi @tarunsapra.

It looks like there is no MySQL traffic coming on port 3306. I suspect your application connects to MySQL via the unix sockets. MySQL needs to listen on _127.0.0.1_ instead of _localhost_ in order to force the application not use the socket. How do you start the MySQL client?

---

<div class="post-metadata">

### Author: ![tarunsapra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarunsapra/32/3903_2.png) [@tarunsapra](https://discuss.elastic.co/u/tarunsapra)
#### Post date: [September 21, 2015, 8:34pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/5 "2015-09-21T20:34:46Z")

</div>

> [@tarunsapra](#):
>
> Also, I logged into mysql using 127.0.0.1 in order to use the port and avoid the socket issue.

Hi @monica , in the first comment of this thread I have shared that i connect via IP address to avoid the unix socket thing. "Also, I logged into mysql using 127.0.0.1 in order to use the port and avoid the socket issue."

mysql -h 127.0.0.1 - u root

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [September 22, 2015, 7:43am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/6 "2015-09-22T07:43:53Z")

</div>

On OSX you need to specify the device when running the tcpdump command.

```
sudo tcpdump -i lo0 -n -s0 -w trace.pcap "port 3306"

```

where lo0 is the localhost interface where MySQL is listening on. The _-n_ option disables the name resolution and it makes the packets show faster.

---

<div class="post-metadata">

### Author: ![tarunsapra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarunsapra/32/3903_2.png) [@tarunsapra](https://discuss.elastic.co/u/tarunsapra)
#### Post date: [September 22, 2015, 9:17am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/7 "2015-09-22T09:17:18Z")

</div>

Hi @monica,

thanks for all the help, it's working on my end now. Here's what was happening -

Your command works fine-

```
sudo tcpdump -i lo0 -n -s0 -w trace.pcap "port 3306"

```

I was doing (which wasn't working, should have checked ifconfig output more prudently)

```
sudo tcpdump -i lo -n -s0 -w trace.pcap "port 3306" (notice the lo without the 0)

```

Now in Mac the default ethernet interface is en0 thus in the packetbeat.yml file in the interface devices it's given en0, when I changes it to lo0 then packetbeats started shipping mysql queries to ES cluster (super cool! 🙂 ) but I want the http queries to be sent to ES cluster as well thus I changed the configuration to  
device: [en0, lo0] which doesn't seem to work, what's your opinion how to give multiple device interfaces in the configuration. The link given in the docs turns out to be broken - [https://www.elastic.co/guide/en/beats/packetbeat/current/\_configuration.html#configuration-interfaces](https://www.elastic.co/guide/en/beats/packetbeat/current/_configuration.html#configuration-interfaces)

Danke.

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [September 22, 2015, 10:15am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/8 "2015-09-22T10:15:12Z")

</div>

Unfortunately on OSX there is no _any_ device like it is on Linux in order to monitor multiple devices. On OSX, a packetbeat instance can monitor a _single_ device. In order to monitor lo0 and en0, you need to start two packetbeat instances, one sniffing on lo0 and one on en0. In the future, we will find a better solution 😄

Here is the link to the documentation: [https://www.elastic.co/guide/en/beats/packetbeat/current/configuration.html#configuration-interfaces](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration.html#configuration-interfaces)

---

<div class="post-metadata">

### Author: ![tarunsapra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarunsapra/32/3903_2.png) [@tarunsapra](https://discuss.elastic.co/u/tarunsapra)
#### Post date: [September 22, 2015, 11:26am UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/9 "2015-09-22T11:26:07Z")

</div>

Hi @monica, thanks for all the help, with multiple packetbeat instances, would be nice if comma separated device values could be supported in the future. Have a nice day.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:58pm UTC](https://discuss.elastic.co/t/unable-to-get-mysql-stats-using-packet-beats/29719/10 "2017-07-05T21:58:45Z")

</div>


