Monitoring Splunk

What are the Database Monitoring features available in Splunk

aparnaa
Path Finder

Hello

Good Day !

We have recently installed splunk and we are monitoring the DB related health after installing Forwarder in DB Servers
Can you please let me know if there are additional features that are available if we use database connect, if yes please let me know if there is any documentation I can refer

If there already a pre-built app that I can refer kindly let me know the details for them also

thank you for helping

thanks
aparna

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

The DB Connect app allows Splunk to read, index or otherwise use actual Database tables, views and queries directly. So for instance if you had your asset list inside some other system that had a DB you could get to, you could use Splunk to read that table into itself for use there, or use it directly as a lookup from Splunk.

Using a forwarding on the DB host gets you their logs, events, and occasionally other information - mostly from the OS level although that's a little blurred because many DB logs are also os-level logs. But it doesn't really allow you to read data from the databases. (Unless you have a job in your DBMS that runs and dumps information into a file on a schedule, you could then use the UF to read that and send it to the indexers).

The various apps and add ons (like this one for SQL Server) is where you get the DB logs that aren't "OS-level" as I mention above, and which allow you to do magical things with the management layer of SQL - collecting audit trails from SQL, or detailed performance information for SQL.

Does that help?

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...