Splunk® Supported Add-ons

Splunk Add-on for Microsoft SQL Server

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for Microsoft SQL Server

Version 2.0.0 of the Splunk Add-on for Microsoft SQL Server was released on November 6, 2020.

About this release

Version 2.0.0 of the Splunk Add-on for Microsoft SQL Server is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.2.x, 7.3.x, 8.0.x and 8.1.0
Splunk DB Connect 2.4.1, 3.1.3, 3.3.1 and 3.4.0
CIM 4.17
Platforms Windows for local data collection on MS SQL Server, platform independent otherwise
Vendor Products Microsoft SQL Server 2012 Enterprise, Microsoft SQL Server 2014 Enterprise, Microsoft SQL Server 2016 Enterprise, Microsoft SQL Server 2019 Enterprise, Microsoft SQL Server 2017 Standard.

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New Features

  • Support for Microsoft SQL Server Standard 2017 and Microsoft SQL Server Enterprise 2019.
  • Compatibility with Splunk DB Connect 3.3.1 and 3.4.0.
  • Added field extractions for the mssql:errorlog and mssql:agentlog sourcetypes.
  • Removed the search time extractions of the host and port field.
    • The value of the host will be the same as the host provided at the time of connection in Splunk DB Connect.
    • For the port field, updated the SQL queries so it will be populated at index-time in the event.
  • Common Information Model (CIM) enhancements:
    • Support for version 4.17.
    • Authentication data model mapping for the logon events in the mssql:errorlog sourcetype.
    • Databases data model mapping for the mssql:databases sourcetype.
    • Removed the serial_num field from the mssql:transaction:dm_tran_locks sourcetype.
    • Additional Splunk IT Service Intelligence (ITSI) database module field compatibility.

For information on upgrading to the newest version of this add-on, see the Upgrade the Splunk Add-on for Microsoft SQL Server topic in this manual.

Fixed issues

Version 2.0.0 of the Splunk Add-on for Microsoft SQL Server has the following fixed issues.


Date resolved Issue number Description
2020-10-22 ADDON-30436 'Additional_Information' field is not getting extracted properly for the 'mssql:audit' sourcetype
2020-09-21 ADDON-29421 Removed incorrect field mapping of serial_num in sourcetype = mssql:transaction:dm_tran_locks

Known issues

Version 2.0.0 of the Splunk Add-on for Microsoft SQL Server has the following known issues.

If no issues appear below, no issues have yet been reported:


Date filed Issue number Description
2014-12-18 ADDON-2753, ADDON-8229 Error in opening perfmon with regex object (SQLServer|MSSQL*) from data inputs UI

Third-party software attributions

Version 2.0.0 of the Splunk Add-on for Microsoft SQL Server does not incorporate any third-party components or libraries.

Last modified on 06 January, 2021
PREVIOUS
Source types for the Splunk Add-on for Microsoft SQL Server
  NEXT
Release history for the Splunk Add-on for Microsoft SQL Server

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters