Database Vault Attempted Violations - Realms

Description

This metric is used to enable Database Vault Security Analyst to keep a watch on the violation attempts against the Database Vault database. Database Vault Security Analyst can pick the realms he would like to get alerted on and even further filter them based on the different types attempts by using error codes. This metric is not enabled out of the box; the user needs to enable it from the Metrics and Policy Settings page. By default this metric is collected every 1 hour, but user can set his own collection frequency.

Metric Summary

The rest of the information in this section is only valid for this metric when it appears in either the Enterprise Manager Grid Control or the Enterprise Manager Database Control (if applicable).

The following table shows how often the metric's value is collected and compared against the default thresholds. The 'Consecutive Number of Occurrences Preceding Notification' column indicates the consecutive number of times the comparison against thresholds should hold TRUE before an alert is generated.

Target Version

Evaluation and Collection Frequency

Upload Frequency

Operator

Default Warning Threshold

Default Critical Threshold

Consecutive Number of Occurrences Preceding Notification

Alert Text

All Versions

Every Hour

Not Uploaded

MATCH

Not Defined

Not Defined

1*

%ACTION_OBJECT_NAME% got violated at %VIOLATIONTIMESTAMP%

* Once an alert is triggered for this metric, it must be manually cleared.

Multiple Thresholds

For this metric you can set different warning and critical threshold values for each unique combination of "Database Vault Realm " and "Violation Time" objects.

If warning or critical threshold values are currently set for any unique combination of "Database Vault Realm " and "Violation Time" objects, those thresholds can be viewed on the Metric Detail page for this metric.

To specify or change warning or critical threshold values for each unique combination of "Database Vault Realm " and "Violation Time" objects, use the Edit Thresholds page. See Editing Thresholds for information on accessing the Edit Thresholds page.

Data Source

The attempted violations are picked up from the target's Database Vault audit trail. Only audit entries related to realms, which represent failed attempts to execute a SQL, are selected.

User Action

To know more about the violations, for example, the realm that was violated, which database user triggered the violation, what action trigged this violation, and at what time this violation happened, login to the target's Database Vault Home Page and use the Attempted Violations charts.

Related Topics

About Alerts

About the Metric Detail Page

Editing Thresholds