Hi,
We have a requirement to install the Splunk add on for sql server.
We are using Splunk cloud with classic experience.
Where all do we need to install this add on? is it sufficient to install on the search head? Or it has to be installed on the heavy forwarder also? Please clarify.
Docs suggest to install on the search head only as the below table.
Splunk instance type Supported Required Comments
Search Heads
Yes
Yes
Install this add-on to all search heads where Microsoft SQL Server knowledge management is required.
Indexers
Yes
No
Not required, because this add-on does not include any index-time operations.
Heavy Forwarders
Yes
No
To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support using a universal or light forwarder installed directly on the machines running MS SQL Server.
Universal Forwarders
Yes
No
To collect dynamic management view data, trace logs, and audit logs, you must use Splunk DB Connect on a search head or heavy forwarder. The remaining data types support file monitoring using a universal or light forwarder installed directly on the machines running MS SQL Server.
... View more