All Apps and Add-ons

How to ingest Microsoft .xel logs

ericlarsen
Path Finder

I have a need to ingest certain SQL Server logs, in a proprietary .xel format, into Splunk.

Do I need to somehow first get these logs into a common file type/format before ingesting them? If so, how would I do that?

Thanks.

0 Karma

badrinath_itrs
Communicator

SPLUNK does not support ingestion of .xel format logs directly, but you can use the sys.fn_xe_file_target_read_file function on the SQL server side to convert the logs and may use DB Connect to ingest the data into SPLUNK .

ericlarsen
Path Finder

Thanks for the response. Since I have a large number of servers, I'm trying to avoid using DB Connect. I was hoping for direct ingestion.

0 Karma

zippo706
Explorer

Hello,

I am curious if you have found another way to accomplish this.    For us, going through audit functions to a blob storage on a heavily used azure sql database is beyond painful and completely impractical.   

0 Karma

arjunpkishore5
Motivator

You can do direct ingestion if they are text files, not proprietary .xel files. So if you can convert them beforehand, then yes

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...