Hello imrago! thank you for your reply!
As you recommended I changed the index to "main", then updated splunk (i had installed 7.1.1 so upgraded to 7.2.1) and changed the search to:
source="udp:514" index="main" sourcetype="logbinder:syslog" product="LOGbinder SQL" targetobjectname=dba
I got results in logbinder app search
I also changed event type logbinder_sql to match this search so it could be used for SQL Activity Report Dashboard (not sure if that is how it works)source="udp:514" index="main" sourcetype="logbinder:syslog" product="LOGbinder SQL"
I'm specificly checking "SQL Login Activity Report", an managed to get it to work!
SQL Overview also works fine, Thank you very much for your help!
Just one more question, I noted datetime fields are on UTC format, which would be the best way to display it according to my timezone?