All Apps and Add-ons

Can Splunk monitor MSSQL database content

BunnyHop
Contributor

I have a MSSQL database that I want to monitor content and indexed by Splunk. I understand there's a 3.x app for this and I'm wondering if there's one that's for 4.x.

Tags (2)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

There isn't exactly a 3.x app for this, but there's is a sample database input polling script that will work for MSSQL. It's just a perl script that polls the DB and provides the output to Splunk, and it should work just as well in 4.x.

View solution in original post

wbfoxii
Communicator

Splunk DB Connect is the way to go!

0 Karma

nchoe123
Engager

Yes, but it's fairly crude; I've heard that it's going to make it into a future version of Splunk.

For now, the python script can get data out of MS SQL and into Splunk, though there's some data massaging that may be required for line breaks etc.

gkanapathy
Splunk Employee
Splunk Employee

There isn't exactly a 3.x app for this, but there's is a sample database input polling script that will work for MSSQL. It's just a perl script that polls the DB and provides the output to Splunk, and it should work just as well in 4.x.

catch_mili
Explorer

@gkanapathy
I want to monitor Ms-sql database & Oracle database, but there we disabled logs from both the databases for performance issue. Still we can monitor database using the mentioned script, If yes then please send me script.

Regards,
catch_mili

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...