<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get SQL server logs into Splunk for Enterprise Security? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109715#M230</link>
    <description>&lt;P&gt;Thank you for your answer,&lt;/P&gt;

&lt;P&gt;But it's not about getting sqlserver logs into Splunk Enterprise, it's about loading it into the Splunk App for Enterprise Security 3.0.1. &lt;BR /&gt;
So i'm looking for an add-on "Security and Compliance" that i can use with ES.&lt;/P&gt;

&lt;P&gt;Have you any idea ?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jan 2015 11:38:59 GMT</pubDate>
    <dc:creator>MinaMina</dc:creator>
    <dc:date>2015-01-23T11:38:59Z</dc:date>
    <item>
      <title>How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109713#M228</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I need to put sql server logs into Splunk for Enterprise Security. Is there any add-on available? I found an Add-on for Oracle, but not for Sqlserver.&lt;/P&gt;

&lt;P&gt;Thx in advance&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2015 22:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109713#M228</guid>
      <dc:creator>MinaMina</dc:creator>
      <dc:date>2015-01-22T22:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109714#M229</link>
      <description>&lt;P&gt;I haven't used SQLServer in a long time, but as I recall a lot of what it records goes into the Windows system logs. The &lt;A href="https://apps.splunk.com/app/1680/"&gt;Splunk App for Windows Infrastructure&lt;/A&gt; or the Universal Forwarder should be able to pick up those records. For anything getting written to an actual log file it should just be a matter of creating a custom file input and directing the data to an index, as described &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/UseSplunkWeb"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2015 23:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109714#M229</guid>
      <dc:creator>pmdba</dc:creator>
      <dc:date>2015-01-22T23:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109715#M230</link>
      <description>&lt;P&gt;Thank you for your answer,&lt;/P&gt;

&lt;P&gt;But it's not about getting sqlserver logs into Splunk Enterprise, it's about loading it into the Splunk App for Enterprise Security 3.0.1. &lt;BR /&gt;
So i'm looking for an add-on "Security and Compliance" that i can use with ES.&lt;/P&gt;

&lt;P&gt;Have you any idea ?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 11:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109715#M230</guid>
      <dc:creator>MinaMina</dc:creator>
      <dc:date>2015-01-23T11:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109716#M231</link>
      <description>&lt;P&gt;Do you have your logs already in Splunk? I'm trying to figure out if the issue is getting the logs themselves in Splunk or getting them tagged and extracted such that they work with ES. I'm just trying to understand so that the I provide the right guidance.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 21:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109716#M231</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2015-01-29T21:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109717#M232</link>
      <description>&lt;P&gt;Not yet, i'm in a planification step. yes, it's about the second one (getting them tagged and extracted such that they work with ES) &lt;BR /&gt;
I found this one &lt;A href="https://apps.splunk.com/app/742/"&gt;https://apps.splunk.com/app/742/&lt;/A&gt;&lt;BR /&gt;
I'm not sure it will work because it wasn't developped for a use with ES.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2015 11:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109717#M232</guid>
      <dc:creator>MinaMina</dc:creator>
      <dc:date>2015-02-01T11:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109718#M233</link>
      <description>&lt;P&gt;Hi MinaMina,&lt;/P&gt;

&lt;P&gt;Thanks for your question. We just published a Splunk Add-on for Microsoft SQL Server: &lt;A href="https://apps.splunk.com/app/2648/"&gt;https://apps.splunk.com/app/2648/&lt;/A&gt;. I hope this helps. &lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2015 16:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109718#M233</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2015-02-26T16:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109719#M234</link>
      <description>&lt;P&gt;@rpille  the addon "Splunk Add-on for Microsoft SQL Server" collects basic data about performance of SQL server &lt;/P&gt;

&lt;P&gt;what i am interested to look at is - &lt;BR /&gt;
- who has accessed the database recently &lt;BR /&gt;
- what change has been made on the database recently &lt;BR /&gt;
- which new user has been created on the DB recently &lt;BR /&gt;
- etc...&lt;/P&gt;

&lt;P&gt;could u plz suggest what has to be done for to get this logs. &lt;/P&gt;

&lt;P&gt;i saw SQL management suite has some logs there, how can we get that forwarded to SPlunk ?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 08:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109719#M234</guid>
      <dc:creator>saurabh_tek</dc:creator>
      <dc:date>2016-10-24T08:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109720#M235</link>
      <description>&lt;P&gt;@saurabh_tek  r u able to find the solution ?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 04:29:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/109720#M235</guid>
      <dc:creator>sumitkathpal292</dc:creator>
      <dc:date>2018-11-13T04:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/509525#M9016</link>
      <description>&lt;P&gt;Did you find a way how to do it please?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 13:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/509525#M9016</guid>
      <dc:creator>saraelamr</dc:creator>
      <dc:date>2020-07-16T13:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to get SQL server logs into Splunk for Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/612107#M11017</link>
      <description>&lt;P&gt;i wanted to get below logs from sql server.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;who has accessed the database recently&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- what change has been made on the database recently&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- which new user has been created on the DB recently&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Add-on for Microsoft SQL Server : do not give above logs. Please suggest&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 13:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-get-SQL-server-logs-into-Splunk-for-Enterprise-Security/m-p/612107#M11017</guid>
      <dc:creator>sonishar</dc:creator>
      <dc:date>2022-09-06T13:55:50Z</dc:date>
    </item>
  </channel>
</rss>

