I will be working on gathering MS SQL audit logs and I should have the option of using DB Connect or using the UF to collect from event logs. To maintain best SQL performance is either a better option?
Splunk 7.3.3, Windows Server 2016, MS SQL 2016 SP2. Any differences for Server and SQL 2019? We'll be migrating to 2019 in the coming months.
What was your conclusion? Which method did you use?