IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Inspection engine in collector not in STAP

  • 1.  Inspection engine in collector not in STAP

    Posted Thu February 01, 2024 11:42 AM

    Hi Experts,

    Should we need to configure inspection engine in collector by navigate  Manage > Activity Monitoring > Inspection Engines ? Not in STAP.

    What will happen if we not configure it in collector? Will it impact any ?

    We have not configured as now  but we are getting logs for the same.

    Refer below link:

    Configuring inspection engines

    Ibm remove preview
    Configuring inspection engines
    An inspection engine extracts SQL from network packets; compiles parse trees that identify sentences, requests, commands, objects, and fields; and logs detailed information about that traffic to an internal database.
    View this on Ibm >


    ------------------------------
    Santhosh M
    ------------------------------


  • 2.  RE: Inspection engine in collector not in STAP

    Posted Fri February 02, 2024 02:45 AM

    Hi Santhosh,

    The short answer is that you don't need to add Inspection Engine in that page if you use S-TAP. 

    As you can see in the document, "An inspection engine extracts SQL from network packets", which means it's for Network TAP (a.k.a N-TAP, or agent-less TAP). This is a very legacy technology and I don't know if there is a customer who is still using this feature.

    Refer to "Network mirroring methods (SPAN , N-TAP) and related inspection engines" to know more about N-TAP. It says "you need to define inspection engines for each of the databases for which the traffic has been mirrored. Note that these inspection engine definitions are different from the definitions with the same name under S-TAP control", and these inspection engine definitions are supposed to be added through Manage > Activity Monitoring > Inspection Engines.

    Note that the Inspection Engine Configuration section in the same page (i.e. Manage > Activity Monitoring > Inspection Engines) are valid for S-TAP. For example, Inspect Returned Data checkbox has to be checked when you need the collector (sniffer) to inspect returned data whatever you use S-TAP / N-TAP.

    Hope it helps,
    Satoshi



    ------------------------------
    SATOSHI KAWASE
    ------------------------------