View more information on alerts.
Option | Definition |
|---|---|
Sensor | The name of the sensor that generated the alert. |
Session ID | The session identification (ID) provided by the DBMS. |
User | The DBMS user. |
Executing User | The user associated with the executed statement that generated the alert. |
Serial | Relevant for Oracle only. The serial number generated by Oracle for this instance of the session. This ID, when taken together with the session ID, provides a unique session identifier. |
OS User | The operating system user. |
Action | The application action. |
CMD Type | The SQL command type. |
Log on time | Relevant for MSSQL only. The time when the user logged on to the application. This field, when taken together with the session ID, provides a unique session identifier. |
Connection Type | The cryptographic protocol used for database communication. |
Instance | The name of the database instance. |
Level | Specifies the alert level such as LOW, MEDIUM, and HIGH. |
DB Container | The database container (only for Oracle 12c Pluggable Databases). |
Application | The application that created the SQL statement that triggered the alert. |
IP | The IP address of the user (if available). |
Net IP | Network IP address. This might differ from the IP reported for an application, and it is applicable when network monitoring is enabled. |
Host Name | The user host name (if available). |
Net Host Name | Network host name. This might differ from the host name reported for an application, and it is applicable only when network monitoring is enabled. |
Terminal | The user terminal (if available). |
Module | The module that generated the alert (if available). |
Client ID | The client ID of the application user that triggered the alert (if available). |
Context Info | Available for MSSQL only. It usually contains the user information. It is used instead of the Application, Module, and Client ID fields that are used in Oracle. |
Local Time | Time instance that relates to the alerting statement. This is conditioned according to the local clock and timezone of the computer where the DBMS resides. |
Statement | The SQL statement that triggered the alert. |
Rules | The rules that generated the alert. Clicking the rule name displays the rule details page for the rule. |
Accessed Objects | The DBMS objects that were accessed as part of the statement operation. |
Inflow SQL | The SQL statement components that originated the action. |
Inflow Objects | The original PL/SQL program units in the DBMS that originated the SQL command. |
Resolution | The state of the alert such as Created Rule, False Alarm, Release From Quarantine, Resolved, Sensor Deleted, and Unresolved. |
Resolved By | The user who resolved the alert. |
Resolved Date | Date when the alert was resolved. |
Reason | The reason for resolving an alert. |