Splunk Enterprise

SPLUNK SQL AUDIT

edgarsilva01
Path Finder
Hello

I have a problem with some .sqlaudit files

These files are being stored in the following path Z: \ audit \
Install a forwarder but Splunk doesn't seem to recognize these files.

Use the Splunk app add-on for SQL Servers, and only be logs of Performance.

Does anyone know how I can get the .sqludit files?
Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
sqlaudit files are not text so they will not be indexed by Splunk. You will need to use a third-party tool to export the sqlaudit file to a text file that can be indexed.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

kamila44cw
Loves-to-Learn Lots

Hi edgarsilva01,

Di you manage to find a solution for this. I am having the same problem. My environment was already setup by someone else, and when I do a search with index=sql I get 10 source which include the ERRORLOG files in MSSQL\Log\ folder and another source called "Index SQL CDS Server Audit", not sure where this source is coming from.

I cannot see any logs originating from the .sqlaudit file

 

Kind Regards..

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

edgarsilva01
Path Finder

Hi Soutamo,

 


The link process is already done, however the output of the files is .sqlaudit and in the same way Splunk does not index them 😞

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

does this https://stackoverflow.com/questions/48345774/output-sqlaudit-file-results-to-text-file-tsql help you? Unfortunately I haven’t any ms sql where to test this. 

r. Ismo

0 Karma

richgalloway
SplunkTrust
SplunkTrust
sqlaudit files are not text so they will not be indexed by Splunk. You will need to use a third-party tool to export the sqlaudit file to a text file that can be indexed.
---
If this reply helps you, Karma would be appreciated.
0 Karma

edgarsilva01
Path Finder

Hi Richgalloway

 

What process do you recommend?

 

Regards

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...