All Apps and Add-ons

Dashboards and Queries for Splunk Add-on for Oracle Database

aliakbar22
New Member

I have installed & configured Splunk Add-on for Oracle Database on Splunk server instance. As per my understanding, this add-on will only facilitate the forwarding of corresponding Oracle system db logs and other information that can be used for database monitoring and performance analysis. However, there are no pre-defined dashboards or search queries to leverage on this data. Can someone please suggest some Splunk search queries or suggest an app to create dashboards displaying info like database status (up or down), queries taking maximum time, problems in db etc?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Also, the add-on does comes with some pre-built panels that you can use in Splunk 6.2 or better... just make a new Dashboard, Add Panel, and look for Oracle down in the prebuilt panels section.

0 Karma

pmdba
Builder

The Splunk Add-on for Oracle is a collection of sample SQL data inputs. There really isn't a lot there to build comprehensive dashboards from, in my opinion. Most of the data being collected in the examples either doesn't change at all (or very rarely), keeps cumulative statistics from the time of database startup (making comparison of different time ranges tricky), or - in my opinion - provides relatively meaningless data that is only valid in the split second in which it was collected.

Using Splunk to collect the kind of performance information you are describing isn't really possible at this time; there are much more specialized tools out there for that purpose. Not saying it couldn't be done with Splunk, but it hasn't been done yet. Splunk's main value at the current time - again, in my opinion - is in collecting log and audit data from Oracle that will allow you to identify and diagnose infrastructure level issues or external (non-SQL related) problems. For a look at how to create your own Oracle monitoring app, including sample inputs in a variety of styles and some dashboard ideas, try taking a look at this: Log File Analysis for Oracle 11g

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...