<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to load SQL Server extended events data to Splunk? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/How-to-load-SQL-Server-extended-events-data-to-Splunk/m-p/369781#M6032</link>
    <description>&lt;P&gt;The Splunk DB Connect app is designed to connect to SQL databases and ingest data from them.  I don't know if it will handle "extended events", but version 3 does support stored procedures.  See &lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;https://splunkbase.splunk.com/app/2686/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2017 13:54:41 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-03-22T13:54:41Z</dc:date>
    <item>
      <title>How to load SQL Server extended events data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-load-SQL-Server-extended-events-data-to-Splunk/m-p/369780#M6031</link>
      <description>&lt;P&gt;I have a requirement to monitor certain activities by few set of SQL Server logins. I will use SQL Server extended events to capture them.  &lt;/P&gt;

&lt;P&gt;I want to load the extended events data back to Splunk and create some alerts based on activities. Such as if a login attempts is tried more than 4 times, an alert should be generated in the real time. &lt;/P&gt;

&lt;P&gt;Is there any way to connect to SQL Server to read extended events records from DMV or xel file or a stored procedure can be called from SQL Server and output can be loaded into Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 12:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-load-SQL-Server-extended-events-data-to-Splunk/m-p/369780#M6031</guid>
      <dc:creator>stripadba</dc:creator>
      <dc:date>2017-03-22T12:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to load SQL Server extended events data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-load-SQL-Server-extended-events-data-to-Splunk/m-p/369781#M6032</link>
      <description>&lt;P&gt;The Splunk DB Connect app is designed to connect to SQL databases and ingest data from them.  I don't know if it will handle "extended events", but version 3 does support stored procedures.  See &lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;https://splunkbase.splunk.com/app/2686/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-load-SQL-Server-extended-events-data-to-Splunk/m-p/369781#M6032</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-03-22T13:54:41Z</dc:date>
    </item>
  </channel>
</rss>

