Splunk Enterprise

SPLUNK SQL AUDIT

edgarsilva01
Path Finder
Hello

I have a problem with some .sqlaudit files

These files are being stored in the following path Z: \ audit \
Install a forwarder but Splunk doesn't seem to recognize these files.

Use the Splunk app add-on for SQL Servers, and only be logs of Performance.

Does anyone know how I can get the .sqludit files?
Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
sqlaudit files are not text so they will not be indexed by Splunk. You will need to use a third-party tool to export the sqlaudit file to a text file that can be indexed.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

kamila44cw
Loves-to-Learn Lots

Hi edgarsilva01,

Di you manage to find a solution for this. I am having the same problem. My environment was already setup by someone else, and when I do a search with index=sql I get 10 source which include the ERRORLOG files in MSSQL\Log\ folder and another source called "Index SQL CDS Server Audit", not sure where this source is coming from.

I cannot see any logs originating from the .sqlaudit file

 

Kind Regards..

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

edgarsilva01
Path Finder

Hi Soutamo,

 


The link process is already done, however the output of the files is .sqlaudit and in the same way Splunk does not index them 😞

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

does this https://stackoverflow.com/questions/48345774/output-sqlaudit-file-results-to-text-file-tsql help you? Unfortunately I haven’t any ms sql where to test this. 

r. Ismo

0 Karma

richgalloway
SplunkTrust
SplunkTrust
sqlaudit files are not text so they will not be indexed by Splunk. You will need to use a third-party tool to export the sqlaudit file to a text file that can be indexed.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi Richgalloway

 

What process do you recommend?

 

Regards

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...