<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk app/work around to track the executed SQL server queries in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523249#M88377</link>
    <description>&lt;P&gt;If you are not able to ingest data that already is produced that contains the query information, you could explore Splunk Stream to pull out the SQL query from the wire data. This could be quite the change so comparing it against enabling the trace log might be a good exercise. If the traffic is encrypted, the cert will be required to decrypt the traffic but you would be able to see the query, transaction times, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following Splunk Lantern use case is very applicable to your question as well using Splunk Stream. &lt;A href="https://lantern.splunk.com/hc/en-us/articles/360053617474-Analyzing-wire-data-from-databases" target="_blank"&gt;https://lantern.splunk.com/hc/en-us/articles/360053617474-Analyzing-wire-data-from-databases&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Oct 2020 18:01:07 GMT</pubDate>
    <dc:creator>dmacintosh_splu</dc:creator>
    <dc:date>2020-10-06T18:01:07Z</dc:date>
    <item>
      <title>splunk app/work around to track the executed SQL server queries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523247#M88376</link>
      <description>&lt;P&gt;&amp;nbsp;I want to track the executed SQL server queries, however I don't want to enable trace log because it would impact SQL server I/O and consume a lot of local space. So, I don't have any sql server trace logs (*.trc files) stored in the server/DB. Is there any work around or splunk app can track the executed SQL server queries?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 17:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523247#M88376</guid>
      <dc:creator>summer</dc:creator>
      <dc:date>2020-10-06T17:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: splunk app/work around to track the executed SQL server queries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523249#M88377</link>
      <description>&lt;P&gt;If you are not able to ingest data that already is produced that contains the query information, you could explore Splunk Stream to pull out the SQL query from the wire data. This could be quite the change so comparing it against enabling the trace log might be a good exercise. If the traffic is encrypted, the cert will be required to decrypt the traffic but you would be able to see the query, transaction times, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following Splunk Lantern use case is very applicable to your question as well using Splunk Stream. &lt;A href="https://lantern.splunk.com/hc/en-us/articles/360053617474-Analyzing-wire-data-from-databases" target="_blank"&gt;https://lantern.splunk.com/hc/en-us/articles/360053617474-Analyzing-wire-data-from-databases&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 18:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523249#M88377</guid>
      <dc:creator>dmacintosh_splu</dc:creator>
      <dc:date>2020-10-06T18:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: splunk app/work around to track the executed SQL server queries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523262#M88380</link>
      <description>&lt;P&gt;Thanks for the quick response. it seems it requires some changes on&amp;nbsp; sql server network setting?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 18:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-app-work-around-to-track-the-executed-SQL-server-queries/m-p/523262#M88380</guid>
      <dc:creator>summer</dc:creator>
      <dc:date>2020-10-06T18:49:56Z</dc:date>
    </item>
  </channel>
</rss>

