Skip to content
Analytics / Database · Two-way sync platform

Splunk and SQL Server integration

Plan how Splunk and SQL Server should share data across your business. Work with Stacksync engineers on record mapping, system access, and the requirements for running the integration.

  • Scope your workflow with an integration engineer
  • Review the systems, records, and updates you need
Integration planning
stacksync.com

Built for teams where self-serve, reliability and scale matter

Case study
Migrated from MuleSoft
Case study
Migrated from Celigo
Migrated from Heroku Connect
Migrated from Matillion
Case study
Migrated from Fivetran
Case study
Migrated from Celigo

Proposed workflow

Metric or analytical result reporting workflow

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Starting eventA change involving Splunk Search Results or the proposed metric or analytical result table in SQL Server needs a defined result in the other system.

  1. Start with Splunk Search Results and the proposed metric or analytical result table in SQL Server. Use the record-matching and field-ownership rules from your mapping worksheet.

  2. Resolve entity keys, time zones, aggregation grain, and any currency/unit conversions.

  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

What to verifyCompare identical time windows and dimensions; test late-arriving data and a recalculated metric.

Review records and field ownership

Proposed record relationships

Records to connect

Use these examples to define record matching and field ownership for your technical review.

Download the mapping worksheet

CSV · No email required

Example record relationships between Splunk and SQL Server
Splunk recordSQL Server recordRecord matchingField ownership
Search ResultsProposed record; confirm Stacksync object support.Reporting datasetProposed metric or analytical result tableProposed table; choose its name and schema.Identify a metric by definition/version, dimensions, time window, and entity key.The analytical model owns the computation; operational systems should receive only approved outputs with freshness context.
HTTP Event CollectorProposed record; confirm Stacksync object support.Reporting datasetProposed event or activity tableProposed table; choose its name and schema.Keep the source event ID, source system, occurrence time, and ingestion time. Use an explicit duplicate-detection key.Decide whether the destination stores an immutable history or only a current-state summary.

These relationships do not establish connector availability. Review the required connection and record operations with Stacksync.

Record coverage to review

Use documented coverage where available. Catalog record types are starting points for review and do not confirm Stacksync support.

Splunk

Connection and object support require review

Record types to review with Stacksync

Record typesCoverage and requirements
  • Search Results
  • Saved Searches
  • Fired Alerts
  • KV Store Collections
  • Indexes
  • HTTP Event Collector
Confirm support for this record type and the direction you need.

Discuss Splunk requirements

SQL Server

Read and write support varies by record

Record types covered in the setup guide

Record typesCoverage and requirements
  • Tables
See connector requirements. Confirm field permissions and sync direction.

Read the SQL Server connector guide

Connection essentials

Confirm Stacksync support and account requirements for undocumented connections. Interface information alone does not establish connector availability.

View setup requirements and limits
Connection requirementSplunkSQL Server
Integration interfaceREST API (management API + HTTP Event Collector)SQL over the TDS wire protocol (Tabular Data Stream), via ODBC/JDBC/ADO.NET drivers
AuthenticationConfirm the credentials, API plan, and permissions required for Splunk.Database credentials entered as a connection string or as parameters
Change detectionConfirm how Stacksync detects changes for this connector and the objects you need.Native SQL Server CDC captures changes after an administrator enables CDC and creates the Stacksync wrapper procedures.
Read accessConfirm with StacksyncAvailable for supported records
Write accessConfirm with StacksyncAvailable for supported records

Enterprise controls

Security and control for your integrations

Explore security controls

Compliance and data transfers

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

  • SOC 2 Type II
  • ISO 27001
  • HIPAA BAA
  • GDPR
  • CCPA
  • DPF US-EU-UK-CH

SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

Secure connection options

Record-level recovery

Inspect sync errors and use retry and revert controls to resolve failed updates.

Read the recovery guide

Implementation

Technical reference

Review setup, record relationships, testing, and recovery for your implementation.

Authentication, permissions and API limits

Connection requirements and limits

Splunk
Integration interface
REST API (management API + HTTP Event Collector)
Authentication
Confirm the credentials, API plan, and permissions required for Splunk.
Change detection
Confirm how Stacksync detects changes for this connector and the objects you need.
Read access
Confirm with Stacksync
Write access
Confirm with Stacksync
Setup requirements
  • Identify the Splunk account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for Splunk, including read/write support, authentication, and initial-load limits.
Limitations to check
  • Confirm Stacksync support for Splunk and the record types your workflow needs.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.
SQL Server
Integration interface
SQL over the TDS wire protocol (Tabular Data Stream), via ODBC/JDBC/ADO.NET drivers
Authentication
Database credentials entered as a connection string or as parameters (host/user/password) in the Create New Sync page
Change detection
Native SQL Server CDC captures changes after an administrator enables CDC and creates the Stacksync wrapper procedures.
Read access
Available for supported records
Write access
Available for supported records
Setup requirements
  • Use a single generated primary key per table and grant the Stacksync user the required table access.
  • Have a DBA run the one-time CDC setup script and grant execution on its wrapper procedures. Verify SQL Server Agent where the deployment requires it.
Limitations to check
  • Composite keys are unsupported. Schema, table, and column renames require updating the sync configuration.
Technical documentation

Documentation reviewed 2026-09-15. Check the linked guides for current account and record requirements.

SQL Server setup guide

Prepare Splunk and SQL Server access

Set up both accounts before testing the mapping. Use test records where available, and identify the account administrator who can approve access and help resolve setup errors.

Splunk setup checklist
  • Identify the Splunk account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for Splunk, including read/write support, authentication, and initial-load limits.
SQL Server setup checklist
  • Use a single generated primary key per table and grant the Stacksync user the required table access.
  • Have a DBA run the one-time CDC setup script and grant execution on its wrapper procedures. Verify SQL Server Agent where the deployment requires it.

Setup guides: Authorize SQL Server

Prepare to go live

Record the fields each system can update, the first-load cutoff, both record IDs, the expected update delay, and who handles errors. Complete the tests before production before expanding to more records.

Use the Splunk and SQL Server planning worksheet to capture these decisions. Record the access owner in the worksheet and enter credentials only in the connection setup.

Talk to an engineer · Review current pricing

Record identity and field ownership

Use these data-model references to describe the records your connection needs. They are planning examples; connector availability and supported operations must be established before implementation.

Download the mapping worksheet · CSV, no email required

Reporting dataset

Search Results / Proposed metric or analytical result table in SQL Server (choose its name)

Plan a metric or analytical result dataset while preserving its source meaning.

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Splunk
Object support to establish
SQL Server
Your database schema
Record identity
Identify a metric by definition/version, dimensions, time window, and entity key.
Field ownership
The analytical model owns the computation; operational systems should receive only approved outputs with freshness context.

Fields to include

  • Metric definition
  • Entity reference
  • Time window
  • Value
  • Computed-at time
Record dependencies
Resolve entity keys, time zones, aggregation grain, and any currency/unit conversions.
Validation
Compare identical time windows and dimensions; test late-arriving data and a recalculated metric.
Recovery
Recompute the intended window before retrying an output; avoid overwriting a newer result with an older computation.

Reporting dataset

HTTP Event Collector / Proposed event or activity table in SQL Server (choose its name)

Plan a event or activity dataset while preserving its source meaning.

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Splunk
Object support to establish
SQL Server
Your database schema
Record identity
Keep the source event ID, source system, occurrence time, and ingestion time. Use an explicit duplicate-detection key.
Field ownership
Decide whether the destination stores an immutable history or only a current-state summary.

Fields to include

  • Source event ID
  • Event type
  • Occurred-at time
  • Related record ID
  • Payload version
Record dependencies
Resolve the related customer, user, or transaction identity without assuming the event ID is the entity ID.
Validation
Deliver the same event twice, then an older event after a newer one; verify duplicate and ordering behavior.
Recovery
Identify side effects already completed before replaying an event; use the agreed deduplication key.

Compare integration approaches

Choose a method around one example record and the update your business needs. Use Search Results / Proposed metric or analytical result table in SQL Server (choose its name) to review record matching and confirm Stacksync support for the required operations. Compare ongoing sync, a custom workflow, and a scheduled export against that requirement.

Stacksync managed sync

Best fit
Review compatibility with a Stacksync engineer using an example of the records and updates you need.
Operating responsibility
Fits ongoing record synchronization when the required operations are supported. Add workflow steps for approvals or business actions that go beyond copying fields.
Before you choose
Check record matching: Identify a metric by definition/version, dimensions, time window, and entity key. Verify field coverage, deletion handling, and how changes are detected.

Native vendor integration

Best fit
A vendor-built integration may fit if it supports your Splunk and SQL Server record types.
Operating responsibility
Can reduce setup for a supported workflow. You may need another method for records or business steps it does not cover.
Before you choose
First check whether either vendor offers this integration. If available, verify Search Results / Proposed metric or analytical result table in SQL Server (choose its name), update direction, account tier, and related-record handling.

Custom API or workflow

Best fit
Consider when Splunk and SQL Server need a transformation, approval, or action outside a direct record sync.
Operating responsibility
Provides control over business steps; the team owns credentials, version changes, error queues, and reconciliation.
Before you choose
Verify endpoint permissions, pagination, quotas, duplicate detection, and failure recovery.

File or scheduled snapshot

Best fit
Consider for a one-time Splunk / SQL Server migration or a reporting need with an explicit freshness window.
Operating responsibility
Can simplify a bounded transfer; later changes and deletion history require another extraction or a separately designed incremental process.
Before you choose
Record the extraction cutoff, source IDs, encoding, date/number formats, and reconciliation totals.

Workflow scenarios and expected results

Metric or analytical result reporting workflow

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Starting event: A change to the selected Search Results or Proposed metric or analytical result table in SQL Server (choose its name) record needs a defined result in the other system.

  1. Start with Splunk Search Results and SQL Server Proposed metric or analytical result table in SQL Server (choose its name). Use the record-matching and field-ownership rules from your mapping worksheet.
  2. Resolve entity keys, time zones, aggregation grain, and any currency/unit conversions.
  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

Expected result: Compare identical time windows and dimensions; test late-arriving data and a recalculated metric.

If it fails: Recompute the intended window before retrying an output; avoid overwriting a newer result with an older computation.

Event or activity reporting workflow

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Starting event: A change to the selected HTTP Event Collector or Proposed event or activity table in SQL Server (choose its name) record needs a defined result in the other system.

  1. Start with Splunk HTTP Event Collector and SQL Server Proposed event or activity table in SQL Server (choose its name). Use the record-matching and field-ownership rules from your mapping worksheet.
  2. Resolve the related customer, user, or transaction identity without assuming the event ID is the entity ID.
  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

Expected result: Deliver the same event twice, then an older event after a newer one; verify duplicate and ordering behavior.

If it fails: Identify side effects already completed before replaying an event; use the agreed deduplication key.

Compare Splunk and SQL Server reporting data

This is an evaluation scenario; connector and operation support require confirmation.

Starting event: An analytical result from Splunk must be reconciled with or displayed alongside a selected destination dataset.

  1. Select Search Results or HTTP Event Collector and record what each row measures, how records are grouped, the timezone, and the reporting cutoff.
  2. Map the analytical entity key to the business record in SQL Server; an aggregate row is not equivalent to an individual transaction.
  3. If an output will be written back, name its owner and carry a computation timestamp so stale results can be recognized.

Expected result: Totals compare the same time window and level of detail; late-arriving data produces a traceable revision rather than an unexplained overwrite.

If it fails: Recompute the selected window and check entity mapping before sending the result again.

Initial load and acceptance testing

Keep both record IDs with the expected and actual result. Reconcile the same filters and time window in each system.

Search Results / Proposed metric or analytical result table in SQL Server (choose its name)

Test case

Compare identical time windows and dimensions; test late-arriving data and a recalculated metric.

Expected result

The expected metric or analytical result relationship is preserved with no duplicate action or unintended write.

HTTP Event Collector / Proposed event or activity table in SQL Server (choose its name)

Test case

Deliver the same event twice, then an older event after a newer one; verify duplicate and ordering behavior.

Expected result

The expected event or activity relationship is preserved with no duplicate action or unintended write.

Direction and permissions

Test case

Bring an example source record and the intended destination operation to the compatibility review. Confirm the supported route before granting write access.

Expected result

Only an approved, supported direction and permitted fields are written.

Freshness and reconciliation

Test case

Measure source and destination times for the selected records under normal load and a burst. Reconcile IDs and values using the same filters and cutoff.

Expected result

The process meets its agreed freshness target and reconciliation has no unexplained differences.

Failed updates, retries and recovery

Start with the failed record and the destination error, then inspect the source value, field requirements, and access.

Rejected or repeated metric or analytical result change

Investigate

Inspect Splunk Search Results and SQL Server Proposed metric or analytical result table in SQL Server (choose its name), their IDs, and the destination error.

Next action

Recompute the intended window before retrying an output; avoid overwriting a newer result with an older computation.

Rejected or repeated event or activity change

Investigate

Inspect Splunk HTTP Event Collector and SQL Server Proposed event or activity table in SQL Server (choose its name), their IDs, and the destination error.

Next action

Identify side effects already completed before replaying an event; use the agreed deduplication key.

A record type or update is unavailable

Investigate

Check the Splunk and SQL Server connector guides, account permissions, and any operations marked On Request.

Next action

Ask the integration team to confirm a supported way to handle that record. Verify whether it needs connector configuration or a separate workflow step.

Source and destination disagree after a retry

Investigate

Compare current source values, destination validation, identity mappings, and any side effects already completed.

Next action

Stacksync issue retry reads the current source state. Decide the intended state before retrying or reverting; reconcile downstream effects separately.

Read the Stacksync issues dashboard guide for retry and revert behavior.

Change detection and update delivery

How updates move between Splunk and SQL Server

See how each system detects changes and which updates the other system can receive. Each direction has its own permissions and record requirements.

Splunk SQL Server Direction requires confirmation

Detect changesConfirm how Stacksync detects changes for this connector and the objects you need.

Apply updatesConfirm that Stacksync can create or update the records you need in SQL Server.

SQL Server Splunk Direction requires confirmation

Detect changesNative SQL Server CDC captures changes after an administrator enables CDC and creates the Stacksync wrapper procedures.

Apply updatesConfirm that Stacksync can create or update the records you need in Splunk.

Update timing and record limits
  • Measure initial-load and ongoing-change latency separately. Source detection, selected objects, account limits, and destination validation determine the observed delay.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.
FAQ

Splunk and SQL Server integration FAQ

Next step

Plan your integration with an engineer

Walk through your Splunk and SQL Server records, field mappings, and requirements with an integration engineer.