Hi,
I'm a little confused which app/add-on I should install.
I have a customer that would like to monitor their production SQL server instances.
However I saw the Microsoft SQL Server App for Splunk is in abandoned status from its page. (Sorry... any replacement? Can I still use it? )
Meanwhile, I looked into Splunk Add-on for Microsoft SQL Server, but I don't feel it has a dashboard for SQL server monitoring/reporting.
From the description, it's more like providing data for PCI/security. Our customer doesn't have Splunk security package.
I read some instructions of these apps how to enable extra audit logs. However, I didn't get how to ingest the audit log.
It's done by performing/WMI? Or I need to add audit log path and tell Splunk correct source type?
Many thanks!
Did you try the new app? https://splunkbase.splunk.com/app/2648/