Default Rule

Learn about the Default rule.

The Default rule specifies the action for any SQL statement that does not meet the criteria of any previous policy rules. When the Database Firewall observes such a statement, the Default rule is applied. The default configuration is to allow the SQL statements without logging them into the Audit Vault Server. A different action in the Default rule can applied along with a substitute statement (optional in case Block action is considered).

To configure the Default rule:

  1. Optionally select Set threshold for escalating action field, if you want to apply a different action after statements fall within the default rule a number of times. Then enter the following:

  2. Select Save.

See Also: Blocking SQL and Creating Substitute Statements

  1. Log in to the Oracle Database Security Central console as an auditor.

  2. Select Policies.

  3. Select Database Firewall Policies in the left navigation menu.

  4. Select the name of an existing policy or select Create to create a new one.

  5. Expand the Default section on the main page.

  6. Select Default Rule.

  7. In the Default dialog, select the values for Action, Logging Level, and Threat Severity fields.

  8. Optionally select Set threshold for escalating action field. Then, enter the following:

    1. Threshold: Enter the number of times a SQL statement must fall within the Default rule before the escalation action is taken.

    2. Threshold Time (in seconds): Enter the time in seconds.

    3. Threshold Action: Select Alert or Block as the action taken after the threshold is met.

    4. Substitution SQL: (Optional) If Block is selected for the Threshold Action field, then enter a substitute for the SQL statement matching this rule.

  9. Select Save.