All Apps and Add-ons

How to install splunk add on for sql server?

ManjunathN
Engager

Hi,

We have a requirement to install the Splunk add on for sql server.

We are using Splunk cloud with classic experience.

Where all do we need to install this add on? is it sufficient to install on the search head? Or it has to be installed on the heavy forwarder also? Please clarify.

Docs suggest to install on the search head only as the below table.

Splunk instance type Supported Required Comments

Search Heads Yes Yes Install this add-on to all search heads where Microsoft SQL Server knowledge management is required.
Indexers Yes No Not required, because this add-on does not include any index-time operations.
Heavy Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support using a universal or light forwarder installed directly on the machines running MS SQL Server.
Universal Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support file monitoring using a universal or light forwarder installed directly on the machines running MS SQL Server.
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

DB Connect should be installed on the SH with inputs disabled.  Install it on an HF and configure the inputs there.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ManjunathN
Engager

where do we need to install this add on - Splunk add on for sql server

Splunk Add-on for Microsoft SQL Server | Splunkbase

We have already DB connect installed on the HF.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  The TA still must be installed on the SH. 

The TA provides templates for DBX so it should be installed alongside DB Connect. 

There are inputs for performance monitoring so you also could install the TA on the SQL server itself if you have a UF installed there.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...