SQL Monitoring -
I'd like to know how to write a Splunk SPL query to alert on the top users running long running SQL queries on my databases. I'm currently using the MS SQL add-on for Splunk and monitoring the included monitors for Perfmon:sqlserver:* and sourcetypes "mssql:agentlog" and "mssql:errorlog"
Thank you in advance!