All Apps and Add-ons

Does the Splunk Add-on for Microsoft SQL Server only work with Enterprise versions, or can we use it with the Standard/Express edition?

charliel
New Member

Looking at the documentation for the Splunk Add-on for Microsoft SQL Server, it specifies that the versions of SQL supported are Enterprise...
http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/About
does this not work on Standard/Express edition? Or can it be installed, but would just be missing some functionality?

0 Karma

Richfez
SplunkTrust
SplunkTrust

It is possible that it only supports certain versions.

In SQL 2005 and SQL 2008 the audit stuff was only in SQL Enterprise. In 2012 MS moved the server audit stuff into SQL Standard, but left the DB audit stuff in Enterprise.

Server audit stuff is like log on, log off, backups - service manipulation and auditing.

Database audit on the other hand can be enabled on individual rows and other data itself.

It could possibly be that it used to require Enterprise, but SQL 2012 and up it'll work OK on Standard and they've just forgotten to update the docs. There's not much harm in trying it in either case.

Richfez
SplunkTrust
SplunkTrust

A good page on the differences in auditing in different versions of SQL can be found here.

0 Karma

charliel
New Member

Hi @ppablo_splunk,

Yes, that is the add-on I'm talking about...looking at this link, for Vendor Products it specifically mentions Enterprise on the SQL Versions:

http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/About

Thanks,

Charlie

0 Karma

ppablo
Retired

Hi @charliel

What add-on specifically from Splunkbase are you referring to when you say "SQL Add-on"?

Are you talking about the Splunk Add-on for Microsoft SQL Server?
https://splunkbase.splunk.com/app/2648/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...