Splunk® Supported Add-ons

Splunk Add-on for Microsoft SCOM

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

SQL queries for SCOM direct events processing reference

The SQL queries provided with the Splunk Add-on for Microsoft SCOM might overload your SCOM Server or Splunk instances.

Splunk support may not be able to assist in cases where you modified your SQL queries. Splunk best practice is to exercise extreme caution during modification of provided SQL queries.

  1. Number of columns are modified at the SQL level for compatibility with scriptlet based source types (All the invocations of ISNULL and LOWER methods).
  2. Number of hard coded columns (splunk_scom_group, scom_command) looks redundant but are required for valid Data Model mapping.
  3. Removal of double quotes from search results: this operation is required to alleviate a known Splunk DB Connect issue: Incomplete field values are extracted when the value contains double quotes
Last modified on 22 February, 2024
PREVIOUS
Lookups for the Splunk Add-on for Microsoft SCOM
 

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters