All Apps and Add-ons

How to install splunk add on for sql server?

ManjunathN
Engager

Hi,

We have a requirement to install the Splunk add on for sql server.

We are using Splunk cloud with classic experience.

Where all do we need to install this add on? is it sufficient to install on the search head? Or it has to be installed on the heavy forwarder also? Please clarify.

Docs suggest to install on the search head only as the below table.

Splunk instance type Supported Required Comments

Search Heads Yes Yes Install this add-on to all search heads where Microsoft SQL Server knowledge management is required.
Indexers Yes No Not required, because this add-on does not include any index-time operations.
Heavy Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support using a universal or light forwarder installed directly on the machines running MS SQL Server.
Universal Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support file monitoring using a universal or light forwarder installed directly on the machines running MS SQL Server.
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

DB Connect should be installed on the SH with inputs disabled.  Install it on an HF and configure the inputs there.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ManjunathN
Engager

where do we need to install this add on - Splunk add on for sql server

Splunk Add-on for Microsoft SQL Server | Splunkbase

We have already DB connect installed on the HF.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  The TA still must be installed on the SH. 

The TA provides templates for DBX so it should be installed alongside DB Connect. 

There are inputs for performance monitoring so you also could install the TA on the SQL server itself if you have a UF installed there.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...