Hi Chase,
Sorry if you get this multiple times, seems like its not posting to the forum properly...
Generally speaking if the DB User is missing due to dropped login packets it will appear as ? and there will be a LOGIN_MISSED exception.
If it is missing due to a specific protocol problem or defect in the product it is usually blank.
There are some specific cases where it will be populated as you note with (OS User). One I know of is for MSSQL traffic with Guardium v9.
In that case before the real DB User is decrypted it will appear as you noted.
If you're not referring to MSSQL on Guardium v9 - Can you clarify:
- What DB and OS is this traffic coming from?
- What is the Guardium version?
Then we can confirm if its expected.
Thanks
Avi
------------------------------
AVRAM WALERIUS
------------------------------
Original Message:
Sent: Wed April 22, 2020 04:11 PM
From: Chase Walkup
Subject: OS User as Database User
Zbigniew,
Thank you. We do not have any computed attributes defined in our environment but I still see this behavior. My question is if this functionality is expected out of the box.
------------------------------
Chase Walkup
------------------------------
Original Message:
Sent: Mon April 20, 2020 12:59 AM
From: Zbigniew (Zibi) Szmigiero
Subject: OS User as Database User
If you refer to report, it is possible
Create computed attribute which produces OS User in case DB Username is empty.
Computed attribute uses MySQL functions where IF condition is available.
------------------------------
Zbigniew (Zibi) Szmigiero
IBM
Warsaw