Splunk® Supported Add-ons

Splunk Add-on for Microsoft SQL Server

Download manual as PDF

Download topic as PDF

The Splunk Add-on for Microsoft SQL Server

Version 1.4.0
Vendor products Microsoft SQL Server 2008 R2 Enterprise, Microsoft SQL Server 2012 Enterprise, Microsoft SQL Server 2014 Enterprise, Microsoft SQL Server 2016 Enterprise
Add-on has a web UI No. This add-on does not contain any views.

The Splunk Add-on for Microsoft SQL Server allows a Splunk software administrator to collect system performance, SQL server performance, log, audit, and status data from Microsoft SQL Server deployments.

The Splunk Add-on for Microsoft SQL Server uses Splunk DB Connect, Splunk Windows Performance monitoring, and file monitoring to collect data. Through log file monitoring and field extraction, the database administrator can correlate events and create alerts and dashboards to track database errors, problems, or incidents in real time.

This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security, the Splunk App for PCI Compliance, and Splunk IT Service Intelligence.

Download the Splunk Add-on for Microsoft SQL Server from Splunkbase.

For a summary of new features, fixed issues, and known issues, see Release Notes for the Splunk Add-on for Microsoft SQL Server.

For information about installing and configuring the Splunk Add-on for Microsoft SQL Server, see Installation and configuration overview for the Splunk Add-on for Microsoft SQL Server.

See Questions related to Splunk Add-on for Microsoft SQL Server on Splunk Answers.

  NEXT
Source types for the Splunk Add-on for Microsoft SQL Server

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Comments

Hello Krotox195,
Not directly, but you can use the sys.fn_xe_file_target_read_file function on the SQL server side. Functionality depends on your version of SQL Server though, as SQL Server 2008 and SQL Server 2008 R2 accept trace results generated in XEL and XEM format. SQL Server 2012 (11.x) only supports trace results in XEL format. Hopefully this helps.
Thanks,
Mike

Mglauser splunk, Splunker
June 27, 2019

Does SQL Server Add-On work with Extended Events? I mean , read directly from extended events xel files?

Krotox195
June 24, 2019

Does SQL Server Add-On work with DB Connect 3.1.3? I am having all sorts of grief getting DB Connect 3.1.3 to work on Windows ... and want I want it for is SQL Server, so I am wondering if I should just step it down to version 2.4 .... especially if the Splunk Add-On for SQL Server is not compatible with DB Connect 3.1.3 ... Is it or not? Thanks.

Kmower
August 28, 2018

Hi.
I have 2 follow-up questions:
1. When does the "official" support for the Standard Edition become available? If the product has not been tested, it is not considered supported.
2. When is SQL 2016 support become available?

Thanks in advance.

SQLDBA
February 27, 2017

Yes, the Splunk Add-on for MS SQL Server also supports SQL server Standard editions. However, this configuration has not been fully tested by engineering so Standard editions are not listed in the doc.

Hunters splunk, Splunker
February 27, 2017

Also, when is SQL 2016 support going to be available? Thanks.

SQLDBA
February 23, 2017

Still not clear about a requirement for the SQL Enterprise Edition. Is it required? Can servers running under the Standard edition be monitored?

SQLDBA
February 23, 2017

Thanks a lot for your feedback, Terry!

The Splunk Add-on for Microsoft SQL Server is used to collect and index various types data from your MS SQL Server deployments for analysis, so if you are using a supported version of MS SQL Server, you should of course have the corresponding license for its usage, but this is a requirement from the MS SQL Server and not a direct prerequisite for using the add-on. In fact, with any Splunk add-on for a commercial third-party product, we assume that the customer already has the appropriate license for using the product.

Hope it helps, thanks!
Hunter Shen
Splunk Docs

Hunters splunk, Splunker
October 31, 2016

Vendor Products: Microsoft SQL Server versions 2008 R2 Enterprise, 2012 Enterprise, and 2014 Enterprise

Does this mean that we can only use this add-on if we have an Enterprise SQL Server license? If so, are there other add-ons that you could suggest if we don't have an Enterprise SQL Server license?

Tyoder
October 31, 2016

CurryRick: Thanks for your feedback. I have added a note with this information to this page as well.

Hjauch splunk, Splunker
September 1, 2015

Never mind, having read further into the documentation I found this: "This add-on does not support DB Connect 2.X at this time." A good place for it indeed, but it would have been equally useful posted here.

CurryRick
September 1, 2015

Not being one to generally assume, will this app work properly with Splunk DB Connect v2?

CurryRick
September 1, 2015

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters