> For the complete documentation index, see [llms.txt](https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/core-features/spectra-ai/data-sources/databases-and-datalakes/mysql.md).

# MySQL

Connecting MySQL to LightBeam

***

## Overview

LightBeam Spectra users can connect various data sources to the LightBeam application and these data sources will be continuously monitored for PII, PHI data.

**Example**: MySQL, MS SQL, Snowflake, SMB, etc.

***

### Onboarding MySQL Data Source

1. Click on **Add Data Source**.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FPRMIoumIIVQhqp2g9fKK%2FMySQL_Add%20Data%20Source%20.png?alt=media&amp;token=28354397-b7e0-49ef-98f3-24b9b2a33de1" alt="" width="375"><figcaption><p>Figure 1. Add Data Source</p></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/mvpnycUHDxQKwHzNMJqseP6pBvd0DsD28rZ5ZLTCf9m5j1A8Bz-Yyqh8UROnVfmESBcD2GJ0oX8wYsFyGQogNuoR8cq9T7QL_LlBQyTa0zIiSDMU_R1_zv7ZS5SAZEXk-3cVIS4UKgZLJ2Fg9xyY7g" alt="" width="375"><figcaption></figcaption></figure>

2. Search for “**MySQL**”.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FtVeDAnJEWmsK1iXzJlRt%2Fimage.png?alt=media&amp;token=840c648f-314f-4001-af07-c0749d4dfb25" alt="" width="375"><figcaption><p>Figure 2. Search for MySQL</p></figcaption></figure>

<figure><img src="https://lh3.googleusercontent.com/HZ161PJOYG0FqoO2aQ30y16EGejw6ZqDocksauVRSFxvFp31SsiVsYvfUJz8b5Ffo97WTIAIw_fJONOgsvTe2ndbLnZP8uPeuBG1n-p3_3lorQgro7JXp4j1Bva2Rkjh0OuONERPPPDT" alt="" width="375"><figcaption></figcaption></figure>

3. Click on **MySQL**.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2Fq4DX03qKEsTnoh3F8IWm%2Fimage.png?alt=media&amp;token=082805bf-f5ae-4585-9d97-3804251c70a5" alt="" width="327"><figcaption><p>Figure 2.1 MySQL Data Source</p></figcaption></figure>

<figure><img src="https://lh3.googleusercontent.com/I6UwREvi9iOEMuojbk5DhsKQse17zQdbeNwdeOTdCEDMqkVn-LsOzYzpZr5cBjykQSVqrV-fTIJnybqi0w3tJXtrLE838MGr2259SHM7r_7kB3jObB8kO8jw7Kn29f7WM45RdxHlpbmk" alt="" width="188"><figcaption></figcaption></figure>

4. &#x20;**Configure Basic Details**

   1. In the **Basic Details** section, fill out the following fields:
      * **Instance Name**: Enter a unique name for the MySQL data source (e.g., `MySQL-Datasource`).
      * **Primary Owner**: Provide the email address of the individual responsible for this data source (e.g., `demo@lightbeam.ai`).
      * **Source of Truth (Optional)**: Toggle this option if the MySQL data source serves as the single point of truth for validating other data sources.
      * **Description** (Optional): Add a brief description (e.g., "MySQL Datasource Instance").

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FdiN6bvMjWTsLrZ8PODHi%2Fimage.png?alt=media&amp;token=3a34ebec-52c1-4381-a7f5-f507c959048c" alt=""><figcaption><p>Figure 3. MySQL Configuration</p></figcaption></figure>

{% hint style="info" %}
**Note**:  Choose the Encrypted option if the server mandates an SSL connection.
{% endhint %}

5. **Enter Connection Details**
   1. In the **Connection** section, provide the following details:
      * **Username**: The MySQL user account name.
      * **Password**: The password for the specified username.
      * **Host**: The hostname or IP address of the MySQL server.
      * **Port**: Specify the port for MySQL. Use the default port (`3306`) or a custom port if applicable.
      * **Encryption**:
        * **Encrypted**: If selected, the options to upload **SSL Certificate**, **SSL Key**, and **SSL CA Certificate** will appear. Upload these files to establish a secure connection.
        * **Unencrypted**: If selected, no additional SSL configuration is required.
      * **SSL Certificate (Optional)**: Upload the SSL certificate file.
      * **SSL Key (Optional)**: Upload the private key file for the SSL connection.
      * **SSL CA Certificate (Optional)**: Upload the Certificate Authority (CA) file to validate the MySQL server.

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2F12ajMLnWnE3D7FYRFHPq%2Fimage.png?alt=media&amp;token=2b267502-af88-4533-aafa-5cb7afd7a414" alt=""><figcaption><p>Figure 4. Datasource credentials</p></figcaption></figure>

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FMrapoHEgdgB0g8d1gO9Q%2FScreenshot%202024-07-19%20at%202.08.06%20PM.png?alt=media&amp;token=600bb867-a513-437d-b5ee-05942ed55fd7" alt="" width="226"><figcaption><p>Figure 5. SSL Connection</p></figcaption></figure>

6. Click on **Test Connection**.<br>
7. Verify that you get the message **“Connection Success!”** on the screen. Click on **Next**.&#x20;

On the next screen, please select databases that you wish to scan from the list.<br>

<figure><img src="https://682442409-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0FnJiPbEPpkm5U4tiZUM%2Fuploads%2FTbPF7fj5nueVNagUpEGi%2FScreenshot%202024-07-19%20at%202.16.15%20PM.png?alt=media&amp;token=91c747a3-2b52-41f5-a635-4a6afef733b3" alt=""><figcaption><p>Figure 6. Configure scan condition</p></figcaption></figure>

Now we are ready to connect to the test database and proceed.

***

## APPENDIX

### Troubleshooting

If you don’t see any data being scanned without error, it might be a permission issue. Consider running a `SELECT *` query on a table and see if you are able to see the data. If you see a message of permission denied, consider granting the permission to the user.

### Minimal permissions setup&#x20;

We require the following permissions to scan only a subset of the databases for the instance:

* **Connect permissions**
* **For each database - `SELECT` permissions**

Use the following script to create a user with such permissions. In this example, we are creating a user with permissions to connect to the LightBeam database.

#### User with restricted permissions for a single database

```
CREATE USER 'test'@'ipaddress or %' IDENTIFIED BY 'lbadmin12345';
GRANT SELECT ON lightbeam.* TO 'test'@'ipaddress or %';
FLUSH PRIVILEGES;
```

The LightBeam UI selection list will only display databases that are added using the second query, which is:

`GRANT SELECT ON lightbeam.* TO 'test'@'ipaddress or %';`

Use the newly formed user to register the MySQL datasource.

#### Full permissions setup

If you want to, you can scan all the databases and allow wider scope permissions. LightBeam recommends a full read-only user that can access a list of databases, connect to every database and read data.

### Validate permissions to the database

Next, the user needs to validate these permissions to the database. This ensures authorized access to the database by the credentials provided by the user. After validating the permissions to the database, the user can configure LightBeam Spectra on the system.

#### Prerequisite

The following tools need to be installed on the system in order to verify database permissions.

* **`Git`**
* **`MySQL tool`**

#### Steps

1. First, clone the repository [`https://github.com/lightbeamai/lb-installer`](https://github.com/lightbeamai/lb-installer)<br>
2. Go into `sql_user_check_mysql/` directory<br>
3. Please refer to the **`README.md`** file in the directory for detailed instructions.

***

## About LightBeam

LightBeam automates Privacy, Security, and AI Governance, so businesses can accelerate their growth in new markets. Leveraging generative AI, LightBeam has rapidly gained customers’ trust by pioneering a unique *privacy-centric* and *automation-first* approach to security. Unlike siloed solutions, LightBeam ties together sensitive data cataloging, control, and compliance across structured and unstructured data applications providing 360-visibility, redaction, self-service DSRs, and automated ROPA reporting ensuring ultimate protection against ransomware and accidental exposures while meeting data privacy obligations efficiently. \
\
LightBeam is on a mission to create a secure privacy-first world helping customers automate compliance against a patchwork of existing and emerging regulations.

For any questions or suggestions, please get in touch with us at: <support@lightbeam.ai>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/core-features/spectra-ai/data-sources/databases-and-datalakes/mysql.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
