IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Capture MongoDB query

    Posted Wed September 18, 2024 09:54 AM

    Hi,

    I am able to setup external stap for our MongoDB running in our K8S cluster and able to see stap status green on guardium appliance but I can not find solution to capture all MongoDB query/API. I have been searched internet but can not find any information regarding MongoDB query capture or rules & policy setup

    Does anyone know it... can help

    Thank you



    ------------------------------
    Support Engineer
    ------------------------------


  • 2.  RE: Capture MongoDB query

    Posted Thu September 19, 2024 05:27 AM

    A lot of issues behind can be

    as a good starting point of troubleshooting:
    1. Confirm that Mongo sessions have need redirected to ETAP ip address and port! You will not see traffic of direct sessions to mongo service
    2. If yes, check ETAP logs



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------



  • 3.  RE: Capture MongoDB query

    Posted Mon October 14, 2024 12:57 AM

    Thank you, I managed to configure to see mongodb query



    ------------------------------
    Support Engineer
    ------------------------------



  • 4.  RE: Capture MongoDB query

    Posted Thu October 17, 2024 10:49 AM

    Hi SE,

    I'm interested to know how you implemented this solution.

    Could you share it, or provide some links, please?

    Explain in which type of server you installed the agent: on the mms: Mongo Monitoring Service, or on the "Shard" , or on the "mongos process" ?

    Thanks.

    Alessandro.



    ------------------------------
    Alessandro Bertucci
    ------------------------------



  • 5.  RE: Capture MongoDB query

    Posted Thu October 17, 2024 11:22 AM

    Hi SE,

    I'm interested to know how you implemented the solution. Could you share it, or provide some links, please?

    Explain in which type of server you installed the agent: on the mms: Mongo Monitoring Service, or on the "Shard" , or on the "mongos process" ?

    Thanks,

    Alessandro.



    ------------------------------
    Alessandro Bertucci
    ------------------------------