Quang,
As Carlos said, you will not be able to see the S-TAP in the 'S-TAP Control' unless you are on the Collector the S-TAP is allocated to, specified during S-TAP installation using the STAP_SQLGUARD_IP parameter. If you are on the Collector and are not seeing the S-TAP in the S-TAP Control then it is likely a port issue.
From the Central Manager you are able to see your deployed S-TAPs using the Enterprise S-TAP View, but this report is not generated in real-time meaning that newly installed S-TAPs may take some time before showing up here. The interval at which this report generates can be
edited.
For your second question, there are a few things that are not correct in your policy that are causing issues. Alert per match is typically not what is used to log activity, and since there are no conditions there is nothing for the policy rule to match. Rule actions that are used to log activity are typically the '
Log Only' and '
Log Full Details' actions. Do not use Log Full Details unless it is absolutely necessary due to the high stress it can have on the Collector.
I recommend that you go to the
Security Learning Academy website. You should be able to use your IBM ID account to get access to their free courses. There are some Guardium courses here that should help you; in particular you should look for the Guardium course named '
Create, install, and update a Guardium policy' under the 'Getting Started with Guardium'
roadmap. This should help you understand more about how to build a policy rule that will log activity.------------------------------
Chase Walkup
------------------------------