Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Allows you to create a new Alert Rule using a selected rule as a template. This action launches the New Alert Rule wizard, each window populated with event criteria from the selected alert rule. You can change any event criterion to meet the goals of your new Alert Rule. SQL Compliance Manager stores the new Alert Rule in the Repository. The selected Alert Rule remains unchanged.

Alerts view

Default columns

Instance name

Provides the name of the audited SQL Server instance where this event occurred.

...

Provides additional information about the alert.

 

Event Alerts view

The Event Alerts view allows you to view previously generated Event Alerts. An Event Alert is generated when the Collection Server processes a SQL Server event that matches the alert rule criteria. Use Event Alerts to identify and investigate suspicious activity on specific databases, users, or instances.

Data Alerts view

The Data Alerts view allows you to view previously generated Data Alerts. A Data Alert is generated when the Collection Server processes a SQL Server event that matches the alert rule criteria. Use Data Alerts to identify and investigate data manipulation on specific databases, tables, or columns.

Info

The Collection Server generates one alert per SELECT event, even though the query may have accessed multiple audited columns.

Status Alerts view

The Status Alerts view allows you to view previously generated Status Alerts. A Status Alert is generated when the status of the specified product components matches the alert rule criteria. Use Status Alerts to identify and investigate possible issues with IDERA SQL Compliance Manager operations, such as deployed agents that may have stopped running.

Alert Rules view

Default columns

Rule

Provides the name you specified when you created each alert rule. By default, SQL Compliance Manager names each new rule New Rule.

Rule Type

Indicates whether this rule generates an Event Alert or a Status Alert.

Server

Provides the name of the registered SQL Server instance associated with this alert rule. By default, Event and Status Alerts apply to all registered SQL Server instances. For better focused Event Alerts, you can specify a different target SQL Server using the Edit Alert Rule wizard.

Level

Provides the alert level, such as High. Depending on the rule type, you can change the alert level using either the Edit Event Alert Rule or Edit Status Alert Rule wizard.

Email

Indicates whether the alert rule criteria includes email notification. When email notification is configured, SQL Compliance Manager sends an alert message to the specified addresses. Depending on the rule type, you can set up email notification using either the Edit Event Alert Rule or Edit Status Alert Rule wizard.

Event Log

Indicates whether the alert rule criteria includes event log notification. When event log notification is configured, SQL Compliance Manager writes an alert message to the application event log. Depending on the rule type, you can set up event log notification using either the Edit Event Alert Rule or Edit Status Alert Rule wizard.

SNMP Trap

Indicates whether the alert rule criteria includes sending SNMP Trap messages to a specified network management console. When SNMP Trap is configured, SQL Compliance Manager sends an alert message to the specified network management console. Depending on the rule type, you can set up SNMP Trap notification using either the Edit Event Alert Rule or Edit Status Alert Rule wizard.

New Event / Data / Status Alert Rule wizard

When you select to create a new alert rule, IDERA SQL Compliance Manager allows you to select whether you want to create an event alert rule, a data alert rule, or a status alert rule. The Add New Rule option allows you to create a new alert using the New Alert Rule wizard. SQL Compliance Manager stores this alert rule in the Repository.

New Event Alert Rule

The Alerts view allows you to specify on which type of SQL Server event you want to alert.

SQL Server Event Type window

The SQL Server Event Type tab allows you to specify on which type of SQL Server event you want to alert.

Available actions

Select type of event that triggers this alert

Allows you to select the SQL Server event type that should trigger this alert. When the Collection Server processes an audited event that matches the specified event type, the alert rule is run to see whether the identified event matches the other alert rule criteria.

You can also select a specific event or a user defined event. A specific event can be any supported SQL Server event that occurs at the server or database level. A user defined event is a custom event you create and track using the sp_trace_generateevent stored procedure.

Edit rule details

Allows you to change your specified alert rule criteria at any time as you create your new alert rule. As you specify criteria using the New Event Alert Rule wizard, the rule details grows to include these additional settings. To edit previously set criteria, click the corresponding setting.

SQL Server Object Type window

The SQL Server Object Type window allows you to specify the type of SQL Server object that should be monitored by this alert rule. You can generate alerts for objects on currently audited databases and SQL Server instances.

Available actions

Select type of event that triggers this alert

Allows you to specify the SQL Server object type that should trigger this alert. When the Collection Server processes an audited event associated with the specified object type, the alert rule is run to see whether the identified event matches the other alert rule criteria.

...

    • Any database whose name contains the word test on the LABSERVER instance
    • The model database on any audited instance
    • The Salary table in the HR01 database hosted by the Chicago instance

Edit rule details

Allows you specify the word or phrase the alert rule should use to identify events associated with the object you want to alert on.

The rule details pane also allows you to change your specified alert rule criteria at any time as you create your new alert rule. As you specify criteria using the New Event Alert Rule wizard, the rule details grows to include these additional settings. To edit previously set criteria, click the corresponding setting

Alert Actions window

The Alert Actions window of the New Event Alert Rule wizard allows you to select the action you want this alert rule to perform when an audited event matches the specified criteria. Depending on the actions you select, IDERA SQL Compliance Manager writes an alert message to the application event log and email it to a specific email address or distribution list. You can use the default alert message or customize it to display the information you need most.

To successfully use email notification, ensure SQL Compliance Manager is configured to connect to your mail server.

Available actions

Select alert action

Allows you to select whether you want an alert message to be generated when this alert is triggered. You can configure an alert message to be written to the application event log and emailed to a specific address or distribution list. SQL Compliance Manager uses the same alert message content for the event log entry and email notification.

Edit rule details

Allows you to specify one or more of the following attributes, depending on the alert action you selected:

    • Content of the alert message
    • Type of event log entry that should be written (Warning, Error, Information)
    • Addresses to which the alert message should be emailed

The rule details pane also allows you to change your specified alert rule criteria at any time as you create your new alert rule. As you specify criteria using the New Event Alert Rule wizard, the rule details grows to include these additional settings. To edit previously set criteria, click the corresponding setting.

Finish Status Alert Rule window

The Finish Alert Rule window of the New Event Alert Rule wizard allows you to specify a name for the new Event Alert rule, review the rule details, and then click Finish. When you finish this wizard, IDERA SQL Compliance Manager enables the alert rule and begins applying your alert criteria against audited events associated with the selected objects.

Available actions

Enable rule now

Indicates that you want SQL Compliance Manager to begin monitoring audited events using this alert rule criteria immediately after you finish creating the rule. By default, all alert rules are enabled upon creation.

 

 

Excerpt
SQL Compliance Manager audits all activity on your server. Learn more > >

 

Save

Save

Save

Save

Save