All Apps and Add-ons

Splunk DB Connect: Logs forwarding

hectorvp
Communicator

Hi Splunkers,

Can we install Splunk DB connect on deployment server to forward MS SQL audit logs to the indexers??

Or is there any alternative way to send MS SQL audit logs without using Splunk DB Connect?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hectorvp,

if your Deployment Server has to manage more than 50 clients it must be dedicated to its role.

If your want to take logs from MS SQL Server you have two solutions:

  • you can use DB-Connect on an Heavy Forwarder,
  • you can create a Store Procedure on MS SQL server that writes logs in a file and install a Universal Forwarder on the MS-SQL server that reads that file, the file can be deleted some minutes after the read action (e.g. after one hour or one day).

Ciao.

Giuseppe

hectorvp
Communicator

Thanks @gcusello ,

By the way we are not trying to fetch MS SQL audit logs to the DS.

We need to forward these audit logs to the customers indexers from our MS SQL servers.

Till now I came to know having Splunk DB connect on DS won't help us to redirect audit logs to the customer indexers, it will fetch logs into DS which we don't want. We don't have HF in our control as well.

The 2nd approach you mentioned is where I'm  looking forward currently.

Only instead of dumping audit logs into a file with some store procedure we would dump it into standard windows event application logs and UF will forward it. Thus is what we are anticipating.

However just was going through community and found a issue mentioned with this approach, which yet personally have not experienced  by me so just need to confirm on same. Below is the link of an issue

https://community.splunk.com/t5/Splunk-Enterprise-Security/Monitoring-MS-SQL-logs-from-Windows-Event...

If this is the case we may need to ask customer to either have CIM modelling for sent logs or then at last need to ask them to fetch logs using Splunk DB connect by themselves.

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It depends.  If the DS is idle enough it should be able to handle the extra workload.  Otherwise, put DBX on a heavy forwarder.

I'll let someone else answer the question about MS SQL audit logs.

---
If this reply helps you, Karma would be appreciated.
0 Karma

hectorvp
Communicator

Thanks @richgalloway , this would help us.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...