# Data collected and exposed in PMM Query Analytics

**URL:** <https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472>\
**Category:** PostgreSQL\
**Tags:** pmm\
**Created:** [November 10, 2022, 6:26am UTC](https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472 "2022-11-10T06:26:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![thy17](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@thy17](https://forums.percona.com/u/thy17)\
**Post date:** [November 10, 2022, 6:26am UTC](https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472/1 "2022-11-10T06:26:53Z")

</div>

The PMM Query Analytics feature allows the user to identify and drill in on the SQL queries that have performance issues.

1. For these SQL statements that are collected by PMM Query Analytics, are the parameter values stored?

E.g. For a SQL statement captured: [select \* from tableA where creditCard=‘1234-5678-1234’;]

Is the creditcard value “1234-5678-1234” also captured by PMM’s internal database, and then also displayed on the PMM/Grafana Dashboard?

My objective is to understand, from security standpoint, whether sensitive database data included in SQL statements will be exposed in PMM database and dashboard.

Specifically, for PostgreSQL DB.

Thank you!

---

<div class="post-metadata">

**Author:** ![Jiri\_Ctvrtka](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/jiri_ctvrtka/32/8302_2.png) [@Jiri\_Ctvrtka](https://forums.percona.com/u/Jiri_Ctvrtka)\
**Post date:** [November 10, 2022, 7:10am UTC](https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472/2 "2022-11-10T07:10:21Z")

</div>

Hi, if you dont want expose data it should be enough disable examples. Then we storing only fingerprint. You can do it by --disable-queryexamples in pmm-admin CLI, or by UI during adding service. Also please check you have latest version of PMM. Let me know if this solved your problem. In next versions of PMM there will be also available run explain without examples.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [November 10, 2022, 7:00pm UTC](https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472/3 "2022-11-10T19:00:02Z")

</div>

Ideally, also, you would encrypt such sensitive information before transmitting to the backend database and store it in encrypted form. This way, even PMM would not be able to see the PCI/PII data.

---

<div class="post-metadata">

**Author:** ![thy17](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@thy17](https://forums.percona.com/u/thy17)\
**Post date:** [November 21, 2022, 2:18am UTC](https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472/4 "2022-11-21T02:18:37Z")

</div>

Hi @Jiri_Ctvrtka and @matthewb , thanks for your pointers!

I would like to seek your help on a few follow-up queries below regarding Sensitive Data Protection using “disable –queryexamples”:

1.1) I saw that we can “SET pg\_stat\_monitor.pgsm\_normalized\_query = true” to avoid disclosing the actual values of parameters in the WHERE clause. Also, we can set “disable --queryexamples” to prevent display of actual parameter values of each query on the QAN dashboard.  
To confirm, do these controls apply to all query statements including SELECT, INSERT, UPDATE, DELETE?  
And are these query statements data stored in the ClickHouse DB or VictoriaMetrics DB?

1.2) Do the above two configurations (i.e. SET pg\_stat\_monitor.pgsm\_normalized\_query = true and disable –queryexamples) apply only if “pg\_stat\_monitor” extension is installed?

1.3) If only the pg\_stat\_statements views are used for PostgreSQL DB metrics collection, then do the above two configurations stated in point 1.2 still apply?

1.4 If only the pg\_stat\_statements views are used for monitoring PostgreSQL DBs, then will PMM still provide additional value-add compared with the traditional Prometheus-Grafana setup?

Thank you!

---

<div class="post-metadata">

**Author:** ![Jiri\_Ctvrtka](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/jiri_ctvrtka/32/8302_2.png) [@Jiri\_Ctvrtka](https://forums.percona.com/u/Jiri_Ctvrtka)\
**Post date:** [December 3, 2022, 8:49am UTC](https://forums.percona.com/t/data-collected-and-exposed-in-pmm-query-analytics/18472/5 "2022-12-03T08:49:39Z")

</div>

@thy17 Hi, about your questions:  
1.1) Yes, it also applies on SELECT, INSERT, UPDATE and DELETE. Its stored in ClickHouse DB used by PMM Server.  
1.2) pg\_stat\_monitor.pgsm\_normalized\_query is applied only for pg\_stat\_monitor. Disable examples is same case, because only pg\_stat\_monitor supports examples at the moment. Pg\_stat\_statements doesnt has this option.  
1.3) Yes it still apply, but it doesnt has any effect.  
1.4) Yes, all our extra values (which we have for pg\_stat\_statements) will be still provided.

Related to this, since next version you can run “EXPLAIN” without “EXAMPLES” for MySQL. PostgreSQL support will be implemented in next versions too. Maybe it will be useful for you.

Thank you.
