Splunk Cloud Platform

How to create a weekly report which covers database operations?

I29851
Explorer

Hello all

I have installed universal forwarder on Databases and now want to create a weekly report which covers database operations, for example table deletion, database modifications etc. Do I need to install any app? Currently forwarders are configured only to collect windows events.

 

Regards

 

Tags (2)
0 Karma
1 Solution

venky1544
Builder

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

View solution in original post

0 Karma

venky1544
Builder

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...