Hi All,
We have integrated MS SQL logs with Splunk. The current default add-on supports logs via DB Connect but we do not have database connectivity directly. Rather, all the logs are written in Security logs for Windows Event viewer with most of the details in the Message field.
Currently all the fields are not being parsed . How can we make it CIM compliant ?
Since the data is not structured as expected by the "default add-on", you will have to craft your own add-on to parse the fields.