Splunk Dev

How to load SQL Server extended events data to Splunk?

stripadba
Engager

I have a requirement to monitor certain activities by few set of SQL Server logins. I will use SQL Server extended events to capture them.

I want to load the extended events data back to Splunk and create some alerts based on activities. Such as if a login attempts is tried more than 4 times, an alert should be generated in the real time.

Is there any way to connect to SQL Server to read extended events records from DMV or xel file or a stored procedure can be called from SQL Server and output can be loaded into Splunk?

Tags (1)

richgalloway
SplunkTrust
SplunkTrust

The Splunk DB Connect app is designed to connect to SQL databases and ingest data from them. I don't know if it will handle "extended events", but version 3 does support stored procedures. See https://splunkbase.splunk.com/app/2686/

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...