<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to add SQL logs without server add-on? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503114#M85707</link>
    <description>&lt;P&gt;Can I add SQL logs without the SQL server add-on? &lt;BR /&gt;
I need to add SQL logs. I've requested to do this on Splunk and also read many Splunk docs, &lt;BR /&gt;
but all of them refer to the add on. &lt;/P&gt;

&lt;P&gt;We don't have it installed and looks like we have no plans to do it in the near future. &lt;BR /&gt;
So, in the meantime, how can I add SQL logs into Splunk 8.0.0?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2019 20:01:14 GMT</pubDate>
    <dc:creator>mhpapa62</dc:creator>
    <dc:date>2019-12-10T20:01:14Z</dc:date>
    <item>
      <title>Is it possible to add SQL logs without server add-on?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503114#M85707</link>
      <description>&lt;P&gt;Can I add SQL logs without the SQL server add-on? &lt;BR /&gt;
I need to add SQL logs. I've requested to do this on Splunk and also read many Splunk docs, &lt;BR /&gt;
but all of them refer to the add on. &lt;/P&gt;

&lt;P&gt;We don't have it installed and looks like we have no plans to do it in the near future. &lt;BR /&gt;
So, in the meantime, how can I add SQL logs into Splunk 8.0.0?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 20:01:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503114#M85707</guid>
      <dc:creator>mhpapa62</dc:creator>
      <dc:date>2019-12-10T20:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to add SQL logs without server add-on?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503115#M85708</link>
      <description>&lt;P&gt;Hi @mhpapa62,&lt;BR /&gt;
if you're speaking of SQL Server logs, they are in the Windows Event Viewer, so you can take this and search for the specific SQL Server EventCodes.&lt;BR /&gt;
The way to take them are different: use the Windows Add-on it's the easiest way, but you can take them also by Splunk Enterprise [Settings -- data Inputs -- Remote event log collections] but this method uses WMI and needs a domain account (I don't like it!).&lt;/P&gt;

&lt;P&gt;It's different if you want to extract data from the database: the easiest way is to use DB-Connect App, otherwise, you could schedule a query on the DB that writes results in a file and then read these files using the Splunk Universal Forwarder.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 08:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503115#M85708</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-12-11T08:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to add SQL logs without server add-on?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503116#M85709</link>
      <description>&lt;P&gt;Thank you Giuseppe. Just a question, are you using Splunk 8? I can't find [Settings -- data Inputs -- Remote event log collections] on Splunk 8 settings. Just [Data, Report acceleration Summaries / Source Types].&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 13:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503116#M85709</guid>
      <dc:creator>mhpapa62</dc:creator>
      <dc:date>2019-12-11T13:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to add SQL logs without server add-on?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503117#M85710</link>
      <description>&lt;P&gt;Hi @mhpapa62,,&lt;BR /&gt;
yes, but WMI is available only on Windows machines, so you should use an Heavy Forwarder instaled on Windows Operative System.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 13:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-add-SQL-logs-without-server-add-on/m-p/503117#M85710</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-12-11T13:50:20Z</dc:date>
    </item>
  </channel>
</rss>

