Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Audited Activities tab allows you to change which types of SQL Server events you want to audit. IDERA SQL Compliance Manager audits these events at the server level only.

Image Added

Available fields

Audited Activity

...

Via SQL Server Audit Specifications - Allows you to select SQL Server Audit Logs as your event handling system for DML and SELECT events for SQL Server 2017 and later versions. For more information about this feature, see Using SQL Server Audit Logs

Anchor
trusted
trusted
Trusted Users tab

The Trusted Users tab of the SQL Server Default Audit Settings window allows you to add Trusted Users at server level and set the default audit settings to be applied on SQL Server instances. You can choose to audit event categories and user defined events. An event category includes related SQL Server events that occur at the server level. A user defined event is a custom event you create and track using the sp_trace_generateevent stored procedure.

Image Added

Available actions

Add

Allows you to select one or more trusted users to audit. You can select trusted users by Server Roles or by Server Logins.

Remove

Allows you to remove the selected SQL Server login or fixed server role from the list of audited trusted users. When you remove the login or role, the SQL Compliance Manager Agent no longer collects events recorded for that login or the role members.

Anchor
privileged
privileged
Privileged User Auditing tab

The Privileged User Auditing tab of the Registered SQL Server Properties Default Audit Settings window allows you to change the add Privileged Users at server level and set the default audit settings currently to be applied to privileged users on this SQL Server instanceinstances. You can choose to audit event categories and user defined events. An event category includes related SQL Server events that occur at the server level. A user defined event is a custom event you create and track using the sp_trace_generateevent stored procedure.

...

When you update audit settings to audit privileged user activities, these changes are not applied until the SQL trace is refreshed. The SQL trace is refreshed when the SQL Compliance Manager Agent sends the trace files to the Collection Server. To ensure an immediate application of your new audit settings, click Update Audit Settings Now on the Agent menu.

Image Modified

Available actions

Add

Allows you to select one or more privileged users to audit. You can select privileged users by login name Server Roles or by membership to a fixed server roleServer Logins.

Remove

Allows you to remove the selected SQL Server login or fixed server role from the list of audited privileged users. When you remove the login or role, the SQL Compliance Manager Agent no longer collects events recorded for that login or the role members.

...

Ensure the Collection Server and the target SQL Server computers have ample resources to handle the additional data collection, storage, and processing. Because this setting can significantly increase resource requirements and negatively impact performance, choose this setting only when your compliance policies require you to audit SQL statements.

Add Users window

...

.

...

Anchor
thresholds
thresholds
Auditing Thresholds tab

The Auditing Thresholds tab of the Registered SQL Server Properties Default Audit Settings window allows you to set auditing thresholds to identify unusual activity on the selected SQL Server instanceinstances. IDERA SQL Compliance Manager reports threshold violations through the Activity Report Cards on the Summary tabs.

Use auditing thresholds to display critical issues or warnings when a particular activity, such as privileged user events, is higher than expected. These thresholds can notify you about issues related to increased activity levels, such as a security breach, that may be occurring on this instance. Auditing thresholds can also inform you when an audited SQL Server instance is becoming non-compliant. Use thresholds to supplement the alert rules you have configured for your environment.

Image Modified

Available fields

Warning

Allows you to specify the number of events you expect to occur in a given event category for the selected time period. When the warning threshold is exceeded, this violation indicates an unusually high number of events. A warning threshold violation can lead to a non-compliant database or SQL Server instance.

...

Allows you to enable (select) or disable (clear) auditing thresholds for a particular event category.

Anchor

...

The Threshold Notification window is accessed by clicking Threshold Notification on the Auditing Threshold tab while viewing Registered SQL Server Properties. Use this window to set up notifications for when thresholds are exceeded. Set up notifications independently for each event threshold. Note that notifications are sent only if both the threshold and notification are enabled. 

Image Removed

Available fields

Event alert level

Allows you to select whether you want the notification sent when the threshold is at Warning and/or Critical level.

Notification type

Allows you to select whether you want notifications by email, Windows event log, and/or SNMP traps. If you select to receive an email notification, you must include a valid email address. If you select to receive SNMP trap notification, you must include the SNMP trap address, port, and community. If you select to receive Windows event log notification, note that the event is logged as informational.

Threshold message

Allows you to create and manage alert notification messages in the Alert Message Template window and then sent to the email address included in the Email Notification area of the Threshold Notification window. Use the list of available variables to help you create an alert notification message that contains all of the important information for the recipient to understand what is affected and how.

Alert Message Template window

The Alert Message Template window is accessed by clicking Threshold Message on the Threshold Notification window while viewing Registered SQL Server Properties. Use this window to create an effective message to be sent to the email address in the Threshold Notification window when thresholds are exceeded. Use the list of available variables to help you create an alert notification message that contains all of the important information for the recipient to understand what is affected and how.

Image Removed

Anchor
advanced
advanced
Advanced tab

The Advanced tab of the Registered SQL Server Properties Default Audit Settings window allows you to configure the following settings:

  • Control the default permission settings on the databases that contain audit data for this SQL Server instance.
  • Indicate whether collected SQL statements should be truncated if they pass the specified character limit. This option is only available if you are auditing SQL statements executed at the server level on this instance.

Image Modified

Available fields

Default Database Permissions

...