# MSSQL Use cases for elasticsearch stack?

**URL:** https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303
**Category:** Beats
**Created:** [November 12, 2017, 1:15pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303 "2017-11-12T13:15:48Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)
#### Post date: [November 12, 2017, 1:15pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/1 "2017-11-12T13:15:48Z")

</div>

Hi Guys,

Can someone please elaborate what could be use cases for MS-SQL? OR Database in general? I mean what kind of dashboards can be created our SQL data?

TIA

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [November 12, 2017, 1:51pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/2 "2017-11-12T13:51:30Z")

</div>

Some use cases I can think of:

- Search use case where relevancy matters. I don't want only to get data that matches but I want to give my users the most relevant results first. Think about it like "Google" for your MSSQL data.
- BI Like use case. I want to give insights to my users. I can compute every night a dashboard in MSSQL by running a batch which is going to aggregate data or I can do that in real time any time I want without having to prepare any script or batch. I just ask for any insight when I actually need it.
- Performance. I want that my users get results in some milliseconds, not seconds or minutes
- Scale. Scaling can be hard and very costly for traditional RDBMS. Not a problem with elasticsearch.
- Offload my MSSQL database. By running queries on elasticsearch instead of MSSQL you will use MSSQL for what it is very good at: storing and getting data by ID (and CRUD in general). Then instead of using lot of CPU for searching on your MSSQL DB you will use Elasticsearch instead. Elasticsearch is built for search.

My 2 cents

---

<div class="post-metadata">

### Author: ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)
#### Post date: [November 12, 2017, 3:42pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/3 "2017-11-12T15:42:04Z")

</div>

I see I am mean since I am network security admin I am looking from that perspective. Like the top query executed, by whom, where is the database accessed, who accessed, modification time etc?

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [November 12, 2017, 4:01pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/4 "2017-11-12T16:01:48Z")

</div>

Something like what packetbeat, filebeat, metricbeat can give you?

---

<div class="post-metadata">

### Author: ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)
#### Post date: [November 12, 2017, 5:15pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/5 "2017-11-12T17:15:05Z")

</div>

Yeah especially filebeat? I mean not sure what could be the use cases for MS-SQL -

Like I need to start logging of SQL server into Windows Event  
Then capture those events from winlogbeat?

---

<div class="post-metadata">

### Author: ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)
#### Post date: [November 12, 2017, 5:36pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/6 "2017-11-12T17:36:58Z")

</div>

To be specific I believe enabling Database and Server audit and let that log into System/Application events and then forward those to elsaticstack.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [November 12, 2017, 5:37pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/7 "2017-11-12T17:37:57Z")

</div>

I moved your question to #beats where I believe you can get more information about what can be done regarding collecting MSSQL service related data.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [November 13, 2017, 6:10pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/8 "2017-11-13T18:10:06Z")

</div>

With beats you can collect any kind of logs MS-SQL can write. If possible I'd prefer logging to files instead of Windows Event Logs. Collecting logs via Windows Event Logs can be much slower in comparison to files.

Regarding packetbeat we does not support TDS right now (See [https://github.com/elastic/beats/issues/149](https://github.com/elastic/beats/issues/149)).

Same for metricbeat. MSSQL would be a great addition to metricbeat. Feel free to open an enhancement request: [https://github.com/elastic/beats/issues](https://github.com/elastic/beats/issues)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 11, 2017, 6:10pm UTC](https://discuss.elastic.co/t/mssql-use-cases-for-elasticsearch-stack/107303/9 "2017-12-11T18:10:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
