Custom rule properties

Prev Next

View and edit the details of a custom rule, including the DBMSs and DBMS groups where the rule is installed.

Option

Definition

Name

The name of the rule.

If

Define the first rule comparator statement.

Exception

Any exception added by the user (normally to prevent false positives).

Then

Action

The specific action to be taken when the conditions of the custom rule are met.

  • Send alert — Sends an alert when the condition of vPatch rule is met.

  • Trelli Database Security Console — Generates an alert on the alert screen, according to the selected alert priority (Low, Medium, or High).

  • SNMP Trap — Sends an alert as an SNMP trap when the rule is matched.

  • Terminate user session — Close a session for a user on the DBMS based on an alert.

    • Quarantine user session — The user is unable to reconnect to DBMS for a predefined number of minutes.

      Note

      Quarantine is done based on the quarantine settings in the System tab. Make sure that you edit the quarantine settings before you enable quarantine on any of your rules.

  • To Archive — Sends the alert only to the archive (without displaying it in the console or any other location). This option is suitable for auditing information that does not require monitoring on a day-to-day basis.

  • Syslog — Sends an alert to the Syslog when the rule is matched.

  • Windows event Log — Sends an alert to the Windows event log when the rule is matched.

  • Log to file — Sends the alert to a log file.

  • Send alert to email — Sends the alert to the specified email addresses.

  • Stop Verifying Additional Rules — Stops the matching process if a rule is matched. This is the default setting when the rule is set to Allow. If this option is not selected, the matching process continues.

  • Allow — Allows the statement to be processed if the rule is matched. This enables you to create an exception to a rule that appears later in the policy.

    • Global Allow Rule — The rule applied to all the databases.

Advanced actions

  • Script — Specify the script to run when a statement matches the rule, for example, SQL*Plus script in Oracle and T-SQL run by OSQL in Microsoft SQL Server.

  • Mask Sensitive Data — Select to prevent the display of sensitive data in alerts.

  • Regular Expression —Enter a regular expression for the sensitive data using standard regular expression syntax.

  • Limit alerts per second — Set the maximum number of alerts to generate per second or select Unlimited (the default value).

  • Limit alerts per session — Set the maximum number of alerts to generate per session or select Unlimited (the default value).

  • Minimum Rows for alert — To trigger an alert only if a minimum number of rows are returned from the database. This option is available only when network monitoring is enabled.

    Note

    If this parameter is set and the minimum number of rows is exceeded, the alert includes a minimum rows exceeded notification.

  • In the Test Regular Expression dialog box, enter a value to be masked, then click Test.

  • Apply action when rule triggers — To apply an action only in response to repetitive or excessive behavior. In the adjacent fields, specify the minimum number of alerts within the number of seconds, minutes or hours, required to trigger the actions. When this option is configured, one alert is generated for multiple instances of the same rule violation.

  • Automatically resolve to — When the rule is matched, the alert will automatically resolve to False Alarm or Resolved. It is used in some cases to remove false positives.

  • Ignore Signed — Prevent the triggering of alerts by signed scripts.

Install On

DBMSs & Groups

The DBMS where the rule is installed.

Tags

The tags assigned to this rule.

Grant edit permission to role/s

By default, all users can edit the properties of a custom rule. To limit the ability to edit the properties of this rule to specific users or users assigned a specific role (role name).

Comments

A free text description or comment on the rule.

Enable Rule

The rule is enabled.

Advanced rules options

Monitoring source

  • Auto — The sources of information are detected and sampled automatically.

  • All — All available sources of information are used.

  • Memory — Information is collected by memory sampling.

  • Network — Information is collected from network traffic.