I have an MS SQLserver writing audit data to a .sqlaudit file. I need to get this data into Splunk. I have DB Connect installed, but I'm not sure how to ingest the .sqlaudit file data. Do I use DB C...
...first step to setting up the database connection is to install theMicrosoft JDBC driver forSQLServer if it is not already installed. Next, you need to create an identity intheSplunk platform for...
...lass for each SplunkAdd-on and addthe respective hosts based ontheSQL version.
Example: ForMicrosoftSQLServer 2016
a) Rename theSplunk_TA_microsoft-sqlserver_2016 and create a separate server...
...s integrated with the UF and using the "SplunkAdd-onforMicrosoftSQLServer"
With that the MS SQL events can be identified by SourceName=MSSQLSERVER or SourceName=MSSQL*
However it d...
I am trying to forward theSQL Data to Splunk by using Universal Forwarder...
Is it possible to get the data inSplunk without using to SQL DB Connect?
if universal forward can forward the d...
...e have UF agent running in all these nodes.
W have downloaded theSQLAdd-on app from splunk base to monitor the file.
Default monitoring stanza provide in MS SQLAdd-onInputs.conf
ERROR L...
...mport. Running '.\splunk.exe list inputstatus' give me 'type = unreadable file type'. I have theSplunkAdd-onforMicrosoftSQLServerinstalled onthe search head, so that should parse the file on...