IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Is there a way to create a policy alert for failed connections to more than one DB server from one client source?

    Posted Wed May 29, 2019 01:05 PM
    Hello, I was wondering if anyone had any ideas as regards if it is possible within Guardium to configure a policy rule which would alert whenever there are x number of unsuccessful login attempts from a single client to multiple databases and/or database servers within a given time frame (eg. 10 minutes) the userid could also differ or be the same - just the same client ip. At present I only have configured a rule to capture x number of failed login attempts for a specific userid which is for a specific server. 
    Many thanks.

    ------------------------------
    David H
    ------------------------------


  • 2.  RE: Is there a way to create a policy alert for failed connections to more than one DB server from one client source?

    Posted Wed May 29, 2019 02:48 PM

    This may offer some assistance.  In the Knowledge Center under Protect > Policies > 'Specify Values and/or Groups of Values in Rules', it says "If the minimum count is greater than 1, count each individual value separately: Enter a dot (.) in the value box, and select nothing from the group list."  With a dot (.) in the value box for OS User and nothing in the Server IP/Server Hostname, it should alert for each OS User with x failed logins in x minutes regardless of the database server.

     

    Thanks!

     

    Frank J Bates Jr

    Database Risk Administration

    Key Technology & Operations

    Mailstop: OH-01-51-5970

    4910 Tiedeman Road, Brooklyn, OH 44144-2338

    Phone: (216) 471-2740

    Frank_J_BatesJr@KeyBank.com

     

    KeyBank

     

    Use the red key.®

     



    This communication may contain privileged and/or confidential information. It is intended solely for the use of the addressee. If you are not the intended recipient, you are strictly prohibited from disclosing, copying, distributing or using any of this information. If you received this communication in error, please contact the sender immediately and destroy the material in its entirety, whether electronic or hard copy. This communication may contain nonpublic personal information about consumers subject to the restrictions of the Gramm-Leach-Bliley Act. You may not directly or indirectly reuse or redisclose such information for any purpose other than to provide the services for which you are receiving the information.

    127 Public Square, Cleveland, OH 44114


    If you prefer not to receive future e-mail offers for products or services from Key
    send an e-mail to mailto:DNERequests@key.com with 'No Promotional E-mails' in the SUBJECT line.






  • 3.  RE: Is there a way to create a policy alert for failed connections to more than one DB server from one client source?

    Posted Thu May 30, 2019 09:00 AM
    I've had this same request in the past and, unfortunately, Client IP is one of the fields that you CANNOT group on with a (.) like we do with DB User.  The solution we used was a Correlation/Threshold Alert that runs on your schedule (10 minutes) looking back over 10 minutes.  Build it against a Failed Login report that groups on Client IP with a count greater than whatever you want your threshold to be and alert as needed.  

    Hope this helps, let us know if this works for you!

    Matt

    ------------------------------
    Matthew Simons
    ------------------------------



  • 4.  RE: Is there a way to create a policy alert for failed connections to more than one DB server from one client source?

    Posted Thu May 30, 2019 11:08 AM
    Many thanks Matt.
    I shall give your suggestion a try.

    ------------------------------
    David Huckle
    ------------------------------