Hello
I have a problem with some .sqlaudit files
These files are being stored in the following path Z: \ audit \
Install a forwarder but Splunk doesn't seem to recognize these files.
Use the Splunk app add-on for SQL Servers, and only be logs of Performance.
Does anyone know how I can get the .sqludit files?
Hi edgarsilva01,
Di you manage to find a solution for this. I am having the same problem. My environment was already setup by someone else, and when I do a search with index=sql I get 10 source which include the ERRORLOG files in MSSQL\Log\ folder and another source called "Index SQL CDS Server Audit", not sure where this source is coming from.
I cannot see any logs originating from the .sqlaudit file
Kind Regards..
Hi
this https://docs.splunk.com/Documentation/AddOns/released/MSSQLServer/SQLServerconfiguration should help you.
r. Ismo
Hi Soutamo,
The link process is already done, however the output of the files is .sqlaudit and in the same way Splunk does not index them 😞
Hi
does this https://stackoverflow.com/questions/48345774/output-sqlaudit-file-results-to-text-file-tsql help you? Unfortunately I haven’t any ms sql where to test this.
r. Ismo
Hi Richgalloway
What process do you recommend?
Regards