Splunk® Supported Add-ons

Splunk Add-on for Microsoft SCOM

SQL queries for SCOM direct events processing reference

The SQL queries provided with the Splunk Add-on for Microsoft SCOM might overload your SCOM Server or Splunk instances.

Splunk support may not be able to assist in cases where you modified your SQL queries. Splunk best practice is to exercise extreme caution during modification of provided SQL queries.

  1. Number of columns are modified at the SQL level for compatibility with scriptlet based source types (All the invocations of ISNULL and LOWER methods).
  2. Number of hard coded columns (splunk_scom_group, scom_command) looks redundant but are required for valid Data Model mapping.
  3. Removal of double quotes from search results: this operation is required to alleviate a known Splunk DB Connect issue: Incomplete field values are extracted when the value contains double quotes
Last modified on 26 August, 2024
Lookups for the Splunk Add-on for Microsoft SCOM  

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters