【问题标题】:Logstash Grok filter mysql slow-queriesLogstash Grok 过滤 mysql 慢查询
【发布时间】:2018-11-05 13:54:36
【问题描述】:

我正在尝试使用 grok 过滤 mysql 慢查询。我需要得到

  • 数据库名称
  • 用户
  • IP
  • 查询时间
  • 命令

有人帮帮我吗?

# User@Host: tysa6775_ua_data[tysa6775_ua_data] @ localhost []  Id:   360
# Query_time: 1.627188  Lock_time: 0.000246 Rows_sent: 5566  Rows_examined: 459414
use tysa6775_au_data1;
SET timestamp=1541421036;
select * from table_rating where id_product=1009 order by ngaytao desc;
# User@Host: tysa6775_ua_data[tysa6775_ua_data] @ localhost []  Id:   360
# Query_time: 0.000569  Lock_time: 0.000308 Rows_sent: 0  Rows_examined: 3
SET timestamp=1541421036;
select * from table_hoidap where id_product=1009 order by ngaytao desc;
# User@Host: tysa6775_ua_data[tysa6775_ua_data] @ localhost []  Id:   360
# Query_time: 0.000349  Lock_time: 0.000208 Rows_sent: 0  Rows_examined: 28
SET timestamp=1541421036;
select * from table_product_like where id_product='1009' and ip_nguoilike='5.188.210.8' order by stt,id desc;

【问题讨论】:

  • 请贴出SHOW TABLE CREATE table_rating的文字结果;在第一个查询中减少 Rows_examined 的建议。要记录慢查询,您可能希望在 my.cnf/my.ini [mysqld] 部分中使用以下内容,A) log_queries_not_using_indexes=OFF B) long_query_time=1 C) slow_query_log_file=slow-query.log D) min_examined_row_limit=1
  • 欢迎来到 stackoverflow 伙伴。如果你发布一个你已经尝试过的例子,看看你在哪里失败并能够帮助你,那就太好了。另外,如果IP不存在,应该从哪里获取IP?你是说楼主吗?尝试改进您的帖子,社区将很乐意为您提供帮助。

标签: mysql elasticsearch logstash


【解决方案1】:

由于您尝试访问的数据分布在日志文件中的多行中,因此您需要使用 multiline codec,它将从这些行中生成一个事件。

【讨论】:

    猜你喜欢
    • 2017-07-18
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2019-04-27
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多