Splunk Cloud Platform

How to create a weekly report which covers database operations?

I29851
Explorer

Hello all

I have installed universal forwarder on Databases and now want to create a weekly report which covers database operations, for example table deletion, database modifications etc. Do I need to install any app? Currently forwarders are configured only to collect windows events.

 

Regards

 

Tags (2)
0 Karma
1 Solution

venky1544
Contributor

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

View solution in original post

0 Karma

venky1544
Contributor

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...