IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  policy for Guardium Successful login in db servers.

    Posted Mon September 11, 2023 06:06 AM

    Hi all need one help, as we have policy for failed logins attempts. Do we have anything or any policy for successful login?

    Thanks,

    Avinash Minj



    ------------------------------
    Avinash Minj
    ------------------------------


  • 2.  RE: policy for Guardium Successful login in db servers.

    Posted Wed September 13, 2023 08:43 AM

    Hi,

    It's very simple, just add 1 column Successful login to detailed session list or any session level report, value 0 means unsuccessful login and 1 means successful.



    ------------------------------
    Regards,
    Rizwan Ali
    Senior Guardium Consultant
    Pakistan
    ------------------------------



  • 3.  RE: policy for Guardium Successful login in db servers.

    Posted Tue January 28, 2025 11:50 AM

    Hi

    How can we configure a rule in Guardium to capture successful logins, and then send those alerts via syslog for monitoring?



    ------------------------------
    José
    ------------------------------



  • 4.  RE: policy for Guardium Successful login in db servers.

    Posted Tue January 28, 2025 01:03 PM

    Hello Jose,

    Just as Rizwan says, you can add a colum in detailed session but that's only for reports.

    For a policy as you say, to trigger every successfull login, follow the next URL 
    IBM Security Guardium : Alert on successful Database logins



    ------------------------------
    Paul Armando Pena Martinez
    ------------------------------



  • 5.  RE: policy for Guardium Successful login in db servers.

    Posted Wed January 29, 2025 04:23 AM

    Hello,

    I did it this way, but there are application accounts that generate thousands of logins... Is it possible to aggregate and register only one login per database every X minutes?



    ------------------------------
    José
    ------------------------------



  • 6.  RE: policy for Guardium Successful login in db servers.

    Posted Wed January 29, 2025 06:14 AM

    Hi Jose,

    You have got many options to filter rule criteria for session level information, only sessions that are matching will be logged. You may specify to log sessions from some specific db user or client ip list. Also, in the rule action you have got many ALert rule actions, you can try Alert once per session probably for this.



    ------------------------------
    Rizwan Ali
    Guardium Administrator
    ------------------------------



  • 7.  RE: policy for Guardium Successful login in db servers.

    Posted Mon February 03, 2025 12:53 PM

    Try to use SLP. Thanks.



    ------------------------------
    LEONID Rodniansky
    ------------------------------



  • 8.  RE: policy for Guardium Successful login in db servers.

    Posted Tue January 28, 2025 01:55 PM

    Hello,

    You can make a session level policy, make a rule in the policy, define session level criteria like if server ip or hostname is 10.x.x.x and in Rule action define Alert per match or session whatever you like and chose syslog.

    Regards,

    Rizwan



    ------------------------------
    Rizwan Ali
    ------------------------------