When you identify an activity in the DBMS that should be monitored or audited, create a rule to monitor such actions in the future.
Application mapping is performed on every DBMS and provides information about activities taking place on the DBMS, including which applications are being run and by which users.
Note
The sensor needs to run for some time (normally a day or two) to collect enough information to use application mapping effectively.
On the Rules page, click the Application Mapping tab, then click Audit Wizard.
From the Select DBMS drop-down list, select the DBMS for which you want to create an audit rule.
Basic statistics are displayed indicating the application actions collected for the selected DBMS.
In the Audit by area, select Full Audit to monitor all elements on the DBMS or select one of the available options from the drop-down list.
The page is refreshed according to the selected option type. The options available are Application, Host, IP, and Schema.
For example, if Application is selected, the page is refreshed to enable you to select one or more applications.
Select the checkboxes where the rule is to apply. For example, if you select audit by Application, you can select one or more applications.
(Optional) To create an exception to the rule, click Edit Filters in the Rule Exceptions area.
The Rule Exceptions area is expanded to display the available exception categories in a tree like hierarchy.
Select the exception category, then select the checkboxes for which the audit needs to be ignored. The resulting exception is displayed in the Exceptions selected text box.
Note
Click Clear exception to deselect the checkbox. You can choose multiple exception categories as required.
Click Create Rule. The rule is validated and added to the Custom Rules list.
The rule configuration is displayed in the Custom Rules tab.
Click Save.
If you would like to refine the rule further, in the Rule statement field, enter the rule comparator statements.