All Apps and Add-ons

Monitoring SQLERR logs

grantcasey
Engager

I'd like to monitor the MSSQL SQLERROR log file, for example i've turned on T1222 and want to get the deadlock output into splunk.

I think i'm just stumped on how to monitor the file named ERRORLOG (with no suffix.)

any tips?

Tags (1)
0 Karma
1 Solution

acbennett3
Engager

ERRORLOG* worked for me - got both current/no extension and archived copies

View solution in original post

acbennett3
Engager

ERRORLOG* worked for me - got both current/no extension and archived copies

David
Splunk Employee
Splunk Employee

Have you tried adding an input for the file path? You should be able to add it, by following this document:

http://www.splunk.com/base/Documentation/latest/admin/MonitorFilesAndDirectories

I believe the file will be located at %PROGRAMFILES%\Microsoft SQL Server\MSSQL.n\MSSQL\LOG\ERRORLOG

Let me know if you run into any problems.

0 Karma

grantcasey
Engager

I know the input path to use, but the file inside that path has no extension which is causing my grief. I can't convince splunk to monitor it.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...