Carrying out a DAM POC at customer place. Facing below issues :
DAM Sensor on DB2 (AIX) is not able to capture query statements in the alerts, when commands are executed using applications such as javaw.exe, CICSAS. There are only 2 kind of alerts generated for it i.e “End Session” when DBA disconnects and “New session” when DBA connects to DB. However, if we execute the commands using Putty then alerts are generated with full information. We also tried with a simple monitor all rule where IP = <client_IP/Database IP> . But still alerts are not getting generated for the queries executed.
In DB2(AIX), DBA is allowed to access and execution of commands though session is terminated and user is quarantined. It happens by post 2-3 attempts of access. i.e first attempt block, second block, third allowed and thereafter.
Session is not getting terminated for Oracle DB. But the same it working fine with MS SQL DB. Alerts are getting generated by triggering the respective Rule.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.