I think I may have just found my own answer... searching through Splunk docs, I see that there is no direct "monitoring" of DB tables and, therefore, a forwarder (such as the "Universal Forwarder" that I have set up) cannot gather data from a DB to pass on to an indexer. However, there is an add-on to Splunk Enterprise ("Splunk DB Connect") that will "import tables, rows, and columns from a database directly into Splunk Enterprise, which indexes the data". I will be talking to our Splunk administrator to see if we can get this add-on implemented. Wish us luck; it should do what we want.
... View more