All Apps and Add-ons

How to install splunk add on for sql server?

ManjunathN
Engager

Hi,

We have a requirement to install the Splunk add on for sql server.

We are using Splunk cloud with classic experience.

Where all do we need to install this add on? is it sufficient to install on the search head? Or it has to be installed on the heavy forwarder also? Please clarify.

Docs suggest to install on the search head only as the below table.

Splunk instance type Supported Required Comments

Search Heads Yes Yes Install this add-on to all search heads where Microsoft SQL Server knowledge management is required.
Indexers Yes No Not required, because this add-on does not include any index-time operations.
Heavy Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support using a universal or light forwarder installed directly on the machines running MS SQL Server.
Universal Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support file monitoring using a universal or light forwarder installed directly on the machines running MS SQL Server.
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

DB Connect should be installed on the SH with inputs disabled.  Install it on an HF and configure the inputs there.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ManjunathN
Engager

where do we need to install this add on - Splunk add on for sql server

Splunk Add-on for Microsoft SQL Server | Splunkbase

We have already DB connect installed on the HF.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  The TA still must be installed on the SH. 

The TA provides templates for DBX so it should be installed alongside DB Connect. 

There are inputs for performance monitoring so you also could install the TA on the SQL server itself if you have a UF installed there.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...