All Apps and Add-ons

Can the Splunk Add-on for Microsoft SQL Server use a Universal forwarder, or does it have to be a Heavy Forwarder?

rtoloczk
Explorer

The documentation specifies a heavy forwarder. Is this truly the case, or can a Universal Forwarder work with this TA?

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, you need a search head or heavy forwarder to run DB Connect and the Add-on at: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Hardwareandsoftwarerequirements

Note that this doesn't mean you should install HF's on all your MS-SQL Servers, we're assuming you'd have remote DB Connect access to the databases and then use UF's to get the log files, like so: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Configuremodularinput

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, you need a search head or heavy forwarder to run DB Connect and the Add-on at: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Hardwareandsoftwarerequirements

Note that this doesn't mean you should install HF's on all your MS-SQL Servers, we're assuming you'd have remote DB Connect access to the databases and then use UF's to get the log files, like so: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Configuremodularinput

Jagmeet_Arora
Engager

Let's say there are 20 MS-SQL servers. Are you suggesting to monitor sql audit log files of binary format using UF on all MS-SQL servers and stream that binary data to a heavy forwarder on a port? How will heavy forwarder be able to decide which specific MS-SQL server instance to connect to for interpreting binary events coming in from multiple MS-SQL server instances on a single port? Can you please share some sample configurations to elaborate your answer?
I also notice that platform of heavy forwarder is mentioned to be windows. So I guess even if you install windows UF on MS-SQL servers, you need another windows machine to create heavy forwarder?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

binary audit logs are different, and they do need db connect.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...