cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
914
Views
15
Helpful
8
Replies

MS SQL logging and parsing

jeff_groesbeck
Level 1
Level 1

Hello. Maybe I am missing something, but is there a way to collect and parse logs (specifically security auditing - logins, etc...) from MS SQL server in MARS? I see that there 'may' be a snare agent for MS SQL, but I don't know if MARS would recognize the events without a custom parser. Any ideas?

Thank you,

Jeff

8 Replies 8

mhellman
Level 7
Level 7

You can collect them, but I don't believe they will be parsed correctly. They [the logins at least] are logged to the application event log. The last time I tested MARS, you COULD NOT configure a reporting device as a Windows host AND custom parse messages. Having them is a good first step I guess. It would be really nice to be able to extend MAR's parsing with custom parsing though. I *think* the next major version of MARS is supposed to fix this somehow.

Thank you for your response. I didn't even think about the fact that I probably can't just 'add' to the host (Windows 2003 server) 'and' create a custom parser for the SQL entries. I am sure that this is still the case. I really hope that this is improved in 6.x.

Thank you again.

OK. I just got in this morning and build a 'test' custom parser. I appears that if I make this a software application, I can apply it to my previously defined Windows server and tell it that it will be receiving the information to be parsed via syslog. Does anyone have any experience doing this for SQL Server?

Thanks again.

while you can do that, I don't think it will work. At least it didn't work when I tried. As I recall, the problem is that the windows parser has a "catch-all" parser that maps to "generic windows event". This parser is applied before your custom parser.

OK. Thanks. That makes sense. I haven't been able to test this yet, so I appreciate you mentioning this.

Thanks.

I would still test it. It's been quite a few versions since I did. Let us know how it goes.

OK. I've been trying everything to see if I can get something to work here, but to no avail. It definitely reports it as a 'general windows application log' entry instead of running it through the custom parser. Every attempt to get any assistance through TAC (wondering about the order the devices were processed) yielded 'It is not supported'. Anyway, thank you very much for your input on this and unfortunately, I was not successful.

thanks for following up. Let's keep our fingers crossed that this is addressed in 6.x.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: