IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Guardium Universal Collection configuration

    Posted Thu January 23, 2025 09:21 AM

    Hello everyone,

    How frequently does the Guardium Universal Collector connect to the database to retrieve logs? How real-time is the log collection in Guardium, and what is the expected delay between a query occurring on the database and it appearing in Guardium? How can the influencing parameters be configured in the UC settings or GUI? Thanks. 



    ------------------------------
    KA
    ------------------------------


  • 2.  RE: Guardium Universal Collection configuration

    Posted Thu January 23, 2025 12:17 PM

    Hi Kola,

    The log retrieval time is configured within the Universal Connector input configuration. There's a parameter: "interval => <seconds>". IBM has them set to a default that varies from one plug-in to the other, most are set for every 2-5 seconds, but you can adjust it to meet your requirements. In my experience, the logs appear in Guardium in less than one minute, but latency is going to differ based the networking between where your Collectors are installed and where the end point is.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 3.  RE: Guardium Universal Collection configuration

    Posted Thu January 23, 2025 06:24 PM

    Thank you. 



    ------------------------------
    Kola Aina
    ------------------------------



  • 4.  RE: Guardium Universal Collection configuration

    Posted Fri January 24, 2025 01:24 AM

    Hello,

    Guardium almost shows it real time if your network is working fine.

    The STAP agent sniffs each network packet and if related to db activity checks the policy rules against it and logs accordingly.



    ------------------------------
    Regards,
    Rizwan Ali
    Senior Guardium Consultant
    Pakistan
    ------------------------------