• /
  • EnglishEspañolFrançais日本語한국어Português
  • Log inStart now

Install & configure NRDOT for MSSQL monitoring with Helm

|View as Markdown

You can install and configure SQL Server monitoring on Kubernetes using the mssql-otel Helm chart. Optionally, the chart can also run a setup job that creates the monitoring login for you.

Important

This chart only supports SQL Server Authentication (username/password). It does not support Windows Authentication, Windows Domain Authentication, or gMSA. The collector always reaches SQL Server remotely over the network, whether it runs on Linux or Windows, self-hosted or on RDS, so SQL authentication works identically in every case. It also reports SQL Server metrics only (no host/infrastructure metrics), since the collector runs as a Kubernetes Deployment rather than on the SQL Server host itself.

Prerequisites

  • Valid New Relic license key.
  • Helm 3.0 or later, and kubectl configured to access your Kubernetes cluster.
  • Network connectivity from your Kubernetes cluster to the SQL Server host (or RDS endpoint) and port:
    • Self-hosted: a routed path to the SQL Server host (VPN, peering, or shared network), and the SQL Server-side firewall must allow the connection's source IP.
    • AWS RDS: VPC peering, a transit gateway, or shared-VPC placement with the RDS instance, and the RDS security group must allow the SQL Server port (1433 by default) from the cluster's egress source.
  • Either a monitoring login you've already created, or SQL Server admin credentials (a sysadmin-role login, such as sa or the RDS master user) so the chart's setup job can create one for you. See Configure monitoring credentials below.

Create the namespace

Create the namespace you'll install into. It must exist before you create any secrets in the next step, since helm install --create-namespace only creates the namespace during the final install step:

bash
$
kubectl create namespace newrelic

Tip

Set it as the default namespace for your current kubectl context so you don't need to pass -n on every command below:

bash
$
kubectl config set-context --current --namespace=newrelic

Configure monitoring credentials

Decide whether you want the chart's setup job to create the SQL Server monitoring login for you, and if not, how you'll supply its credentials:

Configure the Helm values

Set mssql.topology to match your environment:

Value

Description

self-hosted

Self-hosted SQL Server, reached over the network (Linux or Windows host).

rds

SQL Server on AWS RDS.

Use the values.yaml that matches the credential method you chose in the previous step:

Parameter

Description

licenseKey

Your New Relic license key.

otlpEndpoint

Your region's OTLP/HTTP endpoint, as a full URL with scheme: https://otlp.nr-data.net:4318 (US) or https://otlp.eu01.nr-data.net:4318 (EU). For more information, refer to New Relic OTLP endpoints documentation.

mssql.server / mssql.port

Your SQL Server host (or RDS endpoint) and port, reachable from the cluster.

mssql.tls.enabled / mssql.tls.trustServerCertificate

Optional. Set enabled: true to encrypt the connection to SQL Server, and trustServerCertificate: true to skip certificate validation (useful for self-signed certs in test environments).

setupJob.image.repository / setupJob.image.tag

A sqlcmd-capable image used by the setup job. There's no default: Microsoft's freely pullable mcr.microsoft.com/mssql-tools:latest is dated 2017 and unmaintained, so confirm you're comfortable with its age (including unpatched CVEs) before using it, or build a current image yourself from Microsoft's mssql-tools18 apt packages. Only required for secret-based credentials, where the setup job is enabled.

(Optional) Monitor multiple instances from one release

Instead of mssql.*, set mssqlMulti.enabled: true to monitor several SQL Server instances (self-hosted or RDS) from a single collector pod in one release. The two modes are mutually exclusive: don't set mssql.server and mssqlMulti.enabled: true in the same release.

Multi-instance mode has no plain-username/password path: every instance needs its own Kubernetes secret with monitoring credentials. Decide whether you also want the setup job to create each monitoring login for you:

Parameter

Description

mssqlMulti.enabled

Set to true to monitor multiple instances from one release instead of mssql.*. Defaults to false.

mssqlMulti.topology

self-hosted or rds, same meaning as mssql.topology, shared by every instance in this release.

mssqlMulti.databases

List of instances to monitor. Each entry requires a unique name, server (port defaults to 1433), and existingSecret; add sqlAdmin.existingSecret per entry only when setupJob.enabled is true.

Tip

Scrape settings (collection interval, TLS, metrics) apply identically to every instance in mssqlMulti.databases. There's no per-instance override. Use additionalReceiverConfig for anything that needs to differ. The setup job runs once per instance (<release>-setup-<name>) rather than once per release.

Install the Helm chart

  1. Add the New Relic Helm repository:

    bash
    $
    helm repo add newrelic https://helm-charts.newrelic.com
    $
    helm repo update
  2. Install the chart using your values.yaml file:

    bash
    $
    helm upgrade --install mssql-otel newrelic/mssql-otel \
    >
    -n newrelic \
    >
    --create-namespace \
    >
    -f values.yaml

Verify the installation

  1. Check that the setup job completed (if enabled) and the collector pod is running:

    bash
    $
    kubectl get jobs,pods -n newrelic --watch
  2. Run this query in the query builder to confirm data is arriving:

    SELECT count(*) FROM Metric
    WHERE metricName LIKE 'sqlserver.%'
    AND instrumentation.provider = 'opentelemetry'
    SINCE 10 minutes ago

Find and use your data

Once your data is being collected, you can access comprehensive SQL Server database monitoring through the New Relic UI.

To find your SQL Server database entity in New Relic:

  1. Go to one.newrelic.com > All capabilities > Databases.

  2. From the Entity type dropdown, select MSSQL instance, then click Apply.

  3. Select your SQL Server database from the list of entities.

    After setting up SQL Server monitoring with NRDOT, you can:

Metrics reference

Learn about the available metrics collected by the NRDOT Collector.

Troubleshooting

Learn how to troubleshoot your MSSQL monitoring setup in New Relic.

Set up APM-database correlation

Learn how to correlate your application performance with database operations in New Relic.

Copyright © 2026 New Relic Inc.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.