Security

Splunk & Security with Oracle, SQL, Teradata WITHOUT using Enterprise Security

mmensch
Path Finder

Good morning,

I am currently conducting research on using Splunk to monitor 3 types of databases in terms of security events. As the title states, the databases are Oracle, SQL, and Teradata.

The end goal is to write rules using Splunk's SPL to catch and/or prevent fraud, breaches, or anything else in terms of security. Due to the cost of Enterprise Security, I am not considering this at this point in time.

I was wondering if there are any native apps that contain pre-built searches, functions, inputs relating to security? If not, I was wondering what the next best practice would be, such as enabling auditing and sending the audit logs to Splunk, etc... If this is the case, what specific files and/or tables would be useful?

Thanks,
Matt

0 Karma

altink
Builder

Hi @mmensch

If you would accept a partial solution - Oracle only - you can watch for:

Omega Core Audit App for Splunk (at Splunkbase)

Which requires:

Omega Core Audit (at DATAPLUS)

best regards,
Altin Karaulli
DATAPLUS

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is the Splunk Add-on for Oracle (https://splunkbase.splunk.com/app/1910) that may help. There's also an app for Teradata. You don't say what kind of SQL database you have, but there's probably an app for that, too. Check splunkbase.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...