All Apps and Add-ons

Can the Splunk Add-on for Microsoft SQL Server use a Universal forwarder, or does it have to be a Heavy Forwarder?

rtoloczk
Explorer

The documentation specifies a heavy forwarder. Is this truly the case, or can a Universal Forwarder work with this TA?

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, you need a search head or heavy forwarder to run DB Connect and the Add-on at: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Hardwareandsoftwarerequirements

Note that this doesn't mean you should install HF's on all your MS-SQL Servers, we're assuming you'd have remote DB Connect access to the databases and then use UF's to get the log files, like so: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Configuremodularinput

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

Yes, you need a search head or heavy forwarder to run DB Connect and the Add-on at: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Hardwareandsoftwarerequirements

Note that this doesn't mean you should install HF's on all your MS-SQL Servers, we're assuming you'd have remote DB Connect access to the databases and then use UF's to get the log files, like so: http://docs.splunk.com/Documentation/AddOns/latest/MSSQLServer/Configuremodularinput

Jagmeet_Arora
Engager

Let's say there are 20 MS-SQL servers. Are you suggesting to monitor sql audit log files of binary format using UF on all MS-SQL servers and stream that binary data to a heavy forwarder on a port? How will heavy forwarder be able to decide which specific MS-SQL server instance to connect to for interpreting binary events coming in from multiple MS-SQL server instances on a single port? Can you please share some sample configurations to elaborate your answer?
I also notice that platform of heavy forwarder is mentioned to be windows. So I guess even if you install windows UF on MS-SQL servers, you need another windows machine to create heavy forwarder?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

binary audit logs are different, and they do need db connect.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...