Security

Integrate MSSQL standard edition with Splunk

Nawab
Communicator

We need to integrate MSSQL standard edition with splunk, so we tried sending logs to Windows Event Viewer application channel. Now we are getting logs, but the issue is logs are not parsed and we are getting all logs.

My question is if someone has integrated MSSQL standard edition with splunk. how you did it and is data parsed

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab ,

did you installed the SQL-Server Add-On https://splunkbase.splunk.com/app/2648 on the Search Heads and on the Indexers or (if present) on the Heavy Forwarders?

Ciao.

Giuseppe

View solution in original post

0 Karma

Nawab
Communicator

No i didnt because there is no sourcetype or input if logs are coming in application channel

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab ,

you should use the sourcetypes used in the add-on.

Add-on should be installed in the Forwarder used to ingest data and on the Search Heads, used for search tipe parsing activities.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, the Add-On for MSSQL is the supported way of getting audit data from MSSQL databases. If you want to do it another way, you're pretty much on your own.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nawab ,

did you installed the SQL-Server Add-On https://splunkbase.splunk.com/app/2648 on the Search Heads and on the Indexers or (if present) on the Heavy Forwarders?

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The MSSQL Add-On has installation and configuration docs. Did you read them?

https://docs.splunk.com/Documentation/AddOns/released/MSSQLServer/About

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...