Splunk Cloud Platform

How to create a weekly report which covers database operations?

I29851
Explorer

Hello all

I have installed universal forwarder on Databases and now want to create a weekly report which covers database operations, for example table deletion, database modifications etc. Do I need to install any app? Currently forwarders are configured only to collect windows events.

 

Regards

 

Tags (2)
0 Karma
1 Solution

venky1544
Builder

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

View solution in original post

0 Karma

venky1544
Builder

Hi @I29851 

Universal forwarders would not fetch the database operations  there are two ways 

1) use DB connect APP if you have a heavy forwarder install on it configure the parameters  and get the data into splunk  try the steps in this video

https://www.youtube.com/watch?v=H3DxIMh8sb4

or the documentation 

https://docs.splunk.com/Documentation/DBX/3.8.0/DeployDBX/HowSplunkDBConnectworks

 

2) export the Database logs to file and then read the data using UF 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...