All Apps and Add-ons

How to install splunk add on for sql server?

ManjunathN
Engager

Hi,

We have a requirement to install the Splunk add on for sql server.

We are using Splunk cloud with classic experience.

Where all do we need to install this add on? is it sufficient to install on the search head? Or it has to be installed on the heavy forwarder also? Please clarify.

Docs suggest to install on the search head only as the below table.

Splunk instance type Supported Required Comments

Search Heads Yes Yes Install this add-on to all search heads where Microsoft SQL Server knowledge management is required.
Indexers Yes No Not required, because this add-on does not include any index-time operations.
Heavy Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support using a universal or light forwarder installed directly on the machines running MS SQL Server.
Universal Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support file monitoring using a universal or light forwarder installed directly on the machines running MS SQL Server.
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

DB Connect should be installed on the SH with inputs disabled.  Install it on an HF and configure the inputs there.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ManjunathN
Engager

where do we need to install this add on - Splunk add on for sql server

Splunk Add-on for Microsoft SQL Server | Splunkbase

We have already DB connect installed on the HF.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  The TA still must be installed on the SH. 

The TA provides templates for DBX so it should be installed alongside DB Connect. 

There are inputs for performance monitoring so you also could install the TA on the SQL server itself if you have a UF installed there.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...