Splunk® Supported Add-ons

Splunk Add-on for Microsoft SQL Server

Upgrade the Splunk Add-on for Microsoft SQL Server

Use the Install the Splunk Add-on for Microsoft SQL Server topic in this manual to upgrade to the latest version of the Splunk Add-on for Microsoft SQL Server.

Update your inputs with updated templates

Starting in version 2.0.0 of the Splunk Add-on for Microsoft SQL Server, SQL queries in the db_template file extract the host and port fields from the events and no longer provide these fields in the lookup, by default. No change is required for file monitoring and windows performance monitoring inputs.

SQL queries are updated for the following templates:

  • mssql:instance
  • mssql:os:dm_os_performance_counters
  • mssql:table
  • mssql:user
  • mssql:os:dm_os_sys_info
  • mssql:instancestats
  • mssql:execution:dm_exec_sessions
  • mssql:transaction:dm_tran_locks
  • mssql:execution:dm_exec_query_stats


If you use any of these templates, update your inputs with the updated template by performing the following steps:


  1. In a Splunk instance with Splunk DB Connect installed, open Splunk DB Connect.
  2. Navigate to the the Inputs tab.
  3. Navigate an input that uses an updated template. Use the Template column to filter your inputs by template.
  4. In the Actions column, click Edit. The Edit input window appears.
  5. In the Edit input window, click the Refresh icon on the right side
  6. Once the query is reloaded, click the Execute SQL button to execute the updated query.
  7. Click Next.
  8. Save your changes.
  9. Repeat process for each input that uses an updated template.
Last modified on 24 July, 2024
Configure DB Connect v2 inputs for the Splunk Add-on for Microsoft SQL Server   Saved searches for the Splunk Add-on for Microsoft SQL Server

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters