Monitoring Splunk

What are the Database Monitoring features available in Splunk

aparnaa
Path Finder

Hello

Good Day !

We have recently installed splunk and we are monitoring the DB related health after installing Forwarder in DB Servers
Can you please let me know if there are additional features that are available if we use database connect, if yes please let me know if there is any documentation I can refer

If there already a pre-built app that I can refer kindly let me know the details for them also

thank you for helping

thanks
aparna

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

The DB Connect app allows Splunk to read, index or otherwise use actual Database tables, views and queries directly. So for instance if you had your asset list inside some other system that had a DB you could get to, you could use Splunk to read that table into itself for use there, or use it directly as a lookup from Splunk.

Using a forwarding on the DB host gets you their logs, events, and occasionally other information - mostly from the OS level although that's a little blurred because many DB logs are also os-level logs. But it doesn't really allow you to read data from the databases. (Unless you have a job in your DBMS that runs and dumps information into a file on a schedule, you could then use the UF to read that and send it to the indexers).

The various apps and add ons (like this one for SQL Server) is where you get the DB logs that aren't "OS-level" as I mention above, and which allow you to do magical things with the management layer of SQL - collecting audit trails from SQL, or detailed performance information for SQL.

Does that help?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...