All Apps and Add-ons

Splunk DB Connect: Logs forwarding

hectorvp
Communicator

Hi Splunkers,

Can we install Splunk DB connect on deployment server to forward MS SQL audit logs to the indexers??

Or is there any alternative way to send MS SQL audit logs without using Splunk DB Connect?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hectorvp,

if your Deployment Server has to manage more than 50 clients it must be dedicated to its role.

If your want to take logs from MS SQL Server you have two solutions:

  • you can use DB-Connect on an Heavy Forwarder,
  • you can create a Store Procedure on MS SQL server that writes logs in a file and install a Universal Forwarder on the MS-SQL server that reads that file, the file can be deleted some minutes after the read action (e.g. after one hour or one day).

Ciao.

Giuseppe

hectorvp
Communicator

Thanks @gcusello ,

By the way we are not trying to fetch MS SQL audit logs to the DS.

We need to forward these audit logs to the customers indexers from our MS SQL servers.

Till now I came to know having Splunk DB connect on DS won't help us to redirect audit logs to the customer indexers, it will fetch logs into DS which we don't want. We don't have HF in our control as well.

The 2nd approach you mentioned is where I'm  looking forward currently.

Only instead of dumping audit logs into a file with some store procedure we would dump it into standard windows event application logs and UF will forward it. Thus is what we are anticipating.

However just was going through community and found a issue mentioned with this approach, which yet personally have not experienced  by me so just need to confirm on same. Below is the link of an issue

https://community.splunk.com/t5/Splunk-Enterprise-Security/Monitoring-MS-SQL-logs-from-Windows-Event...

If this is the case we may need to ask customer to either have CIM modelling for sent logs or then at last need to ask them to fetch logs using Splunk DB connect by themselves.

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It depends.  If the DS is idle enough it should be able to handle the extra workload.  Otherwise, put DBX on a heavy forwarder.

I'll let someone else answer the question about MS SQL audit logs.

---
If this reply helps you, Karma would be appreciated.
0 Karma

hectorvp
Communicator

Thanks @richgalloway , this would help us.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...