IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Generate an Alert Based on the Returned Row Count

    Posted 11/15/25 10:34 AM

    Hi Community,

    Is it possible to get the row count based on the entered query entered by an user in guardium data protection(12.1V).

    Use case :

    A user is entering a query on the database - select * from customers.customers1; (Schema is customers, table is customers1)

    Now this query returns more than 1000 rows.

    I want an alert triggered when returned row count of 1000 exceeds for a query.

    After the some research, I found an option in 'Other Criteria' --> "Records affected threshold" which has the option to 'exceed row count' but it does not allow me to change the value from '0'. Please find the below screenshot.

    Not sure whether this is the correct approach or not. 

    If you have an insight on this please advice the way I should be taken.

    Regards,

    Inura Katulanda.



    ------------------------------
    Inura Katulanda
    ------------------------------


  • 2.  RE: Generate an Alert Based on the Returned Row Count

    Posted 11/17/25 06:55 AM

    Hi,

    first navigate to inspection engine configuration and make sure "Log Records Affected" box is checked in the collector you need to apply the rule in, << this will restart the inspection engines to take effect. then go to the rule and choose count to be per session or query "per query will be more accurate"

    • By the exceeded row count, that is, when the number of affected records exceeds the number of records that the Guardium sniffer is configured to process at one time)

    If the thresh

    Thanks,

     



    ------------------------------
    Essa Alshaik Ali
    ------------------------------