All Apps and Add-ons

Can the Splunk Add-on for Microsoft SQL Server use a Universal forwarder, or does it have to be a Heavy Forwarder?

rtoloczk
Explorer

The documentation specifies a heavy forwarder. Is this truly the case, or can a Universal Forwarder work with this TA?

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, you need a search head or heavy forwarder to run DB Connect and the Add-on at: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Hardwareandsoftwarerequirements

Note that this doesn't mean you should install HF's on all your MS-SQL Servers, we're assuming you'd have remote DB Connect access to the databases and then use UF's to get the log files, like so: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Configuremodularinput

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, you need a search head or heavy forwarder to run DB Connect and the Add-on at: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Hardwareandsoftwarerequirements

Note that this doesn't mean you should install HF's on all your MS-SQL Servers, we're assuming you'd have remote DB Connect access to the databases and then use UF's to get the log files, like so: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Configuremodularinput

Jagmeet_Arora
Engager

Let's say there are 20 MS-SQL servers. Are you suggesting to monitor sql audit log files of binary format using UF on all MS-SQL servers and stream that binary data to a heavy forwarder on a port? How will heavy forwarder be able to decide which specific MS-SQL server instance to connect to for interpreting binary events coming in from multiple MS-SQL server instances on a single port? Can you please share some sample configurations to elaborate your answer?
I also notice that platform of heavy forwarder is mentioned to be windows. So I guess even if you install windows UF on MS-SQL servers, you need another windows machine to create heavy forwarder?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

binary audit logs are different, and they do need db connect.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...