vPatch rule properties

Prev Next

View and edit the details of a vPatch rule, including the DBMS and DBMS groups where the rule is installed.

Option

Definition

System ID

The ID number of the rule.

Name

The name of the rule.

Description

A short description of the rule.

Exception

Any exception added by the user (normally to prevent false positives).

Action

The specific action to be taken when the conditions of the vPatch rule are met.

  • Send alert — Sends an alert when the condition of vPatch rule is met.

  • Trellix Database Security Console — Generates an alert on the alert screen, according to the selected alert priority, INFO, NOTICE, LOW, MEDIUM, or HIGH.

  • SNMP Trap — Sends an alert as an SNMP trap when the rule is matched.

  • Terminate user session — Close a session for a user on the DBMS based on an alert.

    • Quarantine user session — The user is unable to reconnect to DBMSs for a predefined number of minutes.

  • To Archive — Sends the alert only to the archive (without displaying it in the console or any other location). This option is suitable for auditing information that does not require monitoring on a day-to-day basis.

  • Syslog — Sends an alert to the Syslog when the rule is matched.

  • Windows event Log — Sends an alert to the Windows event log when the rule is matched.

  • Log to file — Sends the alert to a log file.

  • Send alert to email — Sends the alert to the specified email addresses.

Install On

DBMS & Groups

The DBMS where the rule is installed.

Tags

The tags assigned to this rule.

Comments

A free text description or comment on the rule.

Enable Rule

The rule is enabled.

Advanced rules options

Monitoring source

Source of information used to determine compliance with this rule.