Create a mapping exception rule

Prev Next

Use the sample information collected by Database Security about the access to the DBMS, to create exception rules.

After Database Security collects sampled information about the access to the DBMS, the DBMS Access Info tab shows detailed information about the most commonly used clusters of applications, users, IP addresses, and more, which have accessed the DBMS during the sampling period, including a count for each cluster

This information gathered can be used for the following:

  • Create exception rules

    For example, if a rule is created with an exception for a certain combination of IP address, application and user, then this rule will not generate alert or event when the syntax of a rule exception is matched.

  • Create monitoring rules

    For example, alert or audit each time the combination of user x, application y and IP z is detected.

You can define exceptions to your custom rules by creating an Allow rule and placing it before the relevant rules in the Custom Rules list. This option is normally used when you identify an activity that happens often and does not require monitoring. You can also create an Alert rule for a specific combination. This option is used when you identify activity that should be monitored.

  1. On the Rules page, select the Application Mapping tab, then select DBMS Access Info.

  2. From the Select DBMS drop-down list, select the DBMS whose application mapping information you would like to review. Click Apply.

    The application mapping information for the selected DBMS is displayed in the Display Settings table.

  3. (Optional) To filter the display settings for the DBMS, enter the relevant criteria in the filter area, then click Apply.

  4. To create an Allow rule:

    1. Click the Create Allow Rule icon GUID-B381E5EF-B9EE-4B57-96C7-6FDCFA6F538E-low.png in the required row.

      The Allow rule is displayed in Custom Rules tab.

    2. Click Save.

      The Allow rule is created and added to the Custom Rules list.

  5. To create an Alert rule:

    1. Click the Create Alert Rule icon GUID-5EAD6465-FAA0-49F3-9B76-555D379C65FA-low.png in the required row.

      The Alert rule is displayed in Custom Rules tab.

    2. Click Save.

      The Alert rule is created and added to the Custom Rules list.

    3. Configure the Alert rule in the Audit Wizard tab of Application Mapping.

    Repeat for more entries in the table, as required.