Hello all
I have installed universal forwarder on Databases and now want to create a weekly report which covers database operations, for example table deletion, database modifications etc. Do I need to install any app? Currently forwarders are configured only to collect windows events.
Regards
Hi @I29851
Universal forwarders would not fetch the database operations there are two ways
1) use DB connect APP if you have a heavy forwarder install on it configure the parameters and get the data into splunk try the steps in this video
https://www.youtube.com/watch?v=H3DxIMh8sb4
or the documentation
https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks
2) export the Database logs to file and then read the data using UF
Hi @I29851
Universal forwarders would not fetch the database operations there are two ways
1) use DB connect APP if you have a heavy forwarder install on it configure the parameters and get the data into splunk try the steps in this video
https://www.youtube.com/watch?v=H3DxIMh8sb4
or the documentation
https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks
2) export the Database logs to file and then read the data using UF