All Apps and Add-ons

Monitoring SQLERR logs

grantcasey
Engager

I'd like to monitor the MSSQL SQLERROR log file, for example i've turned on T1222 and want to get the deadlock output into splunk.

I think i'm just stumped on how to monitor the file named ERRORLOG (with no suffix.)

any tips?

Tags (1)
0 Karma
1 Solution

acbennett3
Engager

ERRORLOG* worked for me - got both current/no extension and archived copies

View solution in original post

acbennett3
Engager

ERRORLOG* worked for me - got both current/no extension and archived copies

David
Splunk Employee
Splunk Employee

Have you tried adding an input for the file path? You should be able to add it, by following this document:

http://www.splunk.com/base/Documentation/latest/admin/MonitorFilesAndDirectories

I believe the file will be located at %PROGRAMFILES%\Microsoft SQL Server\MSSQL.n\MSSQL\LOG\ERRORLOG

Let me know if you run into any problems.

0 Karma

grantcasey
Engager

I know the input path to use, but the file inside that path has no extension which is causing my grief. I can't convince splunk to monitor it.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...