MSSQL Data
The Splunk Add-on for Microsoft SQL Server is required for the field extraction.
Splunkbase Download: https://splunkbase.splunk.com/app/2648
Installation and Configuration Guide: https://docs.splunk.com/Documentation/AddOns/released/MSSQLServer/About
The Cyences App has support following data collection mechanisms
- Window Application log using Splunk Add-on for Microsoft Windows (Recommended)
- Audit table using Splunk DB Connect app
-
Azure MSSQL using Splunk Add-on for Microsoft Cloud Services
-
Enable Audit Log: https://learn.microsoft.com/en-us/azure/mysql/single-server/concepts-audit-logs
-
Collect using Azure Event Hub Input: https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/Configureeventhubs/
- Use
mssql:audit:json
as sourcetype when creating input
- Use
-
Note: Use both index=mssql for data collection or update the macro definition for cs_mssql
(Settings > Configuration).
Estimated Data Size
The license usage consumed by the Splunk Add-on for Microsoft SQL Server is based on the audit policy and database usage of your environment