All Apps and Add-ons

Splunk DB Connect: Logs forwarding

Communicator

Hi Splunkers,

Can we install Splunk DB connect on deployment server to forward MS SQL audit logs to the indexers??

Or is there any alternative way to send MS SQL audit logs without using Splunk DB Connect?

 

0 Karma

SplunkTrust
SplunkTrust

Hi @hectorvp,

if your Deployment Server has to manage more than 50 clients it must be dedicated to its role.

If your want to take logs from MS SQL Server you have two solutions:

  • you can use DB-Connect on an Heavy Forwarder,
  • you can create a Store Procedure on MS SQL server that writes logs in a file and install a Universal Forwarder on the MS-SQL server that reads that file, the file can be deleted some minutes after the read action (e.g. after one hour or one day).

Ciao.

Giuseppe

Communicator

Thanks @gcusello ,

By the way we are not trying to fetch MS SQL audit logs to the DS.

We need to forward these audit logs to the customers indexers from our MS SQL servers.

Till now I came to know having Splunk DB connect on DS won't help us to redirect audit logs to the customer indexers, it will fetch logs into DS which we don't want. We don't have HF in our control as well.

The 2nd approach you mentioned is where I'm  looking forward currently.

Only instead of dumping audit logs into a file with some store procedure we would dump it into standard windows event application logs and UF will forward it. Thus is what we are anticipating.

However just was going through community and found a issue mentioned with this approach, which yet personally have not experienced  by me so just need to confirm on same. Below is the link of an issue

https://community.splunk.com/t5/Splunk-Enterprise-Security/Monitoring-MS-SQL-logs-from-Windows-Event...

If this is the case we may need to ask customer to either have CIM modelling for sent logs or then at last need to ask them to fetch logs using Splunk DB connect by themselves.

 

0 Karma

SplunkTrust
SplunkTrust

It depends.  If the DS is idle enough it should be able to handle the extra workload.  Otherwise, put DBX on a heavy forwarder.

I'll let someone else answer the question about MS SQL audit logs.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Communicator

Thanks @richgalloway , this would help us.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!