All Apps and Add-ons

How to install splunk add on for sql server?

ManjunathN
Engager

Hi,

We have a requirement to install the Splunk add on for sql server.

We are using Splunk cloud with classic experience.

Where all do we need to install this add on? is it sufficient to install on the search head? Or it has to be installed on the heavy forwarder also? Please clarify.

Docs suggest to install on the search head only as the below table.

Splunk instance type Supported Required Comments

Search Heads Yes Yes Install this add-on to all search heads where Microsoft SQL Server knowledge management is required.
Indexers Yes No Not required, because this add-on does not include any index-time operations.
Heavy Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support using a universal or light forwarder installed directly on the machines running MS SQL Server.
Universal Forwarders Yes No To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support file monitoring using a universal or light forwarder installed directly on the machines running MS SQL Server.
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

DB Connect should be installed on the SH with inputs disabled.  Install it on an HF and configure the inputs there.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ManjunathN
Engager

where do we need to install this add on - Splunk add on for sql server

Splunk Add-on for Microsoft SQL Server | Splunkbase

We have already DB connect installed on the HF.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for clarifying.  The TA still must be installed on the SH. 

The TA provides templates for DBX so it should be installed alongside DB Connect. 

There are inputs for performance monitoring so you also could install the TA on the SQL server itself if you have a UF installed there.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...