<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the Database Monitoring features available in Splunk in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-Database-Monitoring-features-available-in-Splunk/m-p/227538#M6670</link>
    <description>&lt;P&gt;The &lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;DB Connect app&lt;/A&gt; allows Splunk to read, index or otherwise use actual Database tables, views and queries directly.  So for instance if you had your asset list inside some other system that had a DB you could get to, you could use Splunk to read that table into itself for use there, or use it directly as a lookup from Splunk.&lt;/P&gt;

&lt;P&gt;Using a forwarding on the DB host gets you their logs, events, and occasionally other information - mostly from the OS level although that's a little blurred because many DB logs are also os-level logs.  But it doesn't really allow you to read &lt;EM&gt;data&lt;/EM&gt; from the databases.  (Unless you have a job in your DBMS that runs and dumps information into a file on a schedule, you could then use the UF to read that and send it to the indexers).&lt;/P&gt;

&lt;P&gt;The various apps and add ons (like this one for &lt;A href="https://splunkbase.splunk.com/app/2648/"&gt;SQL Server&lt;/A&gt;) is where you get the DB logs that aren't "OS-level" as I mention above, and which allow you to do magical things with the management layer of SQL - collecting audit trails &lt;EM&gt;from SQL&lt;/EM&gt;, or detailed performance information &lt;EM&gt;for SQL&lt;/EM&gt;.  &lt;/P&gt;

&lt;P&gt;Does that help?&lt;/P&gt;</description>
    <pubDate>Sun, 02 Oct 2016 12:32:59 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2016-10-02T12:32:59Z</dc:date>
    <item>
      <title>What are the Database Monitoring features available in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-Database-Monitoring-features-available-in-Splunk/m-p/227537#M6669</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;Good Day !&lt;/P&gt;

&lt;P&gt;We have recently installed splunk and we are monitoring the DB related health after installing Forwarder in DB Servers&lt;BR /&gt;
Can you please let me know if there are additional features that are available if we use database connect, if yes please let me know if there is any documentation I can refer&lt;/P&gt;

&lt;P&gt;If there already a pre-built app that I can refer kindly let me know the details for them also&lt;/P&gt;

&lt;P&gt;thank you for helping&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
aparna&lt;/P&gt;</description>
      <pubDate>Sun, 02 Oct 2016 08:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-Database-Monitoring-features-available-in-Splunk/m-p/227537#M6669</guid>
      <dc:creator>aparnaa</dc:creator>
      <dc:date>2016-10-02T08:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: What are the Database Monitoring features available in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-Database-Monitoring-features-available-in-Splunk/m-p/227538#M6670</link>
      <description>&lt;P&gt;The &lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;DB Connect app&lt;/A&gt; allows Splunk to read, index or otherwise use actual Database tables, views and queries directly.  So for instance if you had your asset list inside some other system that had a DB you could get to, you could use Splunk to read that table into itself for use there, or use it directly as a lookup from Splunk.&lt;/P&gt;

&lt;P&gt;Using a forwarding on the DB host gets you their logs, events, and occasionally other information - mostly from the OS level although that's a little blurred because many DB logs are also os-level logs.  But it doesn't really allow you to read &lt;EM&gt;data&lt;/EM&gt; from the databases.  (Unless you have a job in your DBMS that runs and dumps information into a file on a schedule, you could then use the UF to read that and send it to the indexers).&lt;/P&gt;

&lt;P&gt;The various apps and add ons (like this one for &lt;A href="https://splunkbase.splunk.com/app/2648/"&gt;SQL Server&lt;/A&gt;) is where you get the DB logs that aren't "OS-level" as I mention above, and which allow you to do magical things with the management layer of SQL - collecting audit trails &lt;EM&gt;from SQL&lt;/EM&gt;, or detailed performance information &lt;EM&gt;for SQL&lt;/EM&gt;.  &lt;/P&gt;

&lt;P&gt;Does that help?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Oct 2016 12:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-Database-Monitoring-features-available-in-Splunk/m-p/227538#M6670</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-10-02T12:32:59Z</dc:date>
    </item>
  </channel>
</rss>

