Splunk Cloud Platform

How to create a weekly report which covers database operations?

I29851
Explorer

Hello all

I have installed universal forwarder on Databases and now want to create a weekly report which covers database operations, for example table deletion, database modifications etc. Do I need to install any app? Currently forwarders are configured only to collect windows events.

 

Regards

 

Tags (2)
0 Karma
1 Solution

venky1544
Builder

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

View solution in original post

0 Karma

venky1544
Builder

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...