All Apps and Add-ons

Can Splunk read SQL Server audit .sqlaudit log files ?

alow_mas
New Member

Am logging all the SQL Server audit logs to the .sqlaudit files. Can the Splunk agent forwarder read such files and forward them to the indexer ?

Tks

0 Karma

chrismewett
Explorer

three years later, there's a different solution:
Splunk Add-on for Microsoft SQL Server - docs here:

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

This app may be of interest to you. Docs here.

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...