The SQL Audit management feature supports seamless transmission of database audit logs to external storage systems (such as ElasticSearch or SLS), significantly enhancing database operation visibility and security. Through efficient log management and in-depth analysis capabilities, it helps enterprises achieve refined operations and risk control, effectively ensuring data security, business continuity, and compliance requirements.
This topic describes the procedure for managing SQL Audit.
Prerequisites
- Please modify the cluster parameter: enable_sql_audit to true to enable the global SQL audit feature.
- Please ensure that the external storage data sources ElasticSearch or SLS are configured. For details, see Connect SQL Audit to ElasticSearch or Connect SQL Audit to SLS.
Procedure
Log in to OCP.
In the left navigation bar, click Cluster. The system enters the Clusters page by default.
On the Clusters page, select the target cluster and click its name to go to the cluster Overview page.
In the left navigation bar of the displayed page, click SQL Audit Management.
In the Basic Information section, click Configure and select a tenant in the dialog box.
Notice
- The SQL audit data of the selected tenant will be transmitted to the following external storage. When a new tenant is added or an existing tenant is deleted, to avoid unsynchronized SQL audit data or duplicate tenant names, the system will automatically update the OCP Agent parameters.
- If you select All, the SQL audit data of all current tenants and future newly created tenants will be transmitted to the subsequently configured external storage. You can filter by using Exclude Objects.
Select an external storage.
Configure the Log Database, which is the name of the SLS service logstore.
Click Save.
In the confirmation dialog box, click OK.
Related operations
Edit SQL Audit: In the upper-right corner of the Basic Information section, click Edit. Modify the relevant information in the pop-up dialog box, then click Save.
Delete SQL Audit: In the Basic Information section, turn off the Enabled switch. In the pop-up dialog box, click Disable. Then, in the upper-right corner of the Basic Information section, click Delete. Finally, in the confirmation dialog box, click OK.
View SQL Audit: Below the Basic Information section, you can view the Number of Objects Written to Object Storage. You can customize the time in the time filter box in the upper-right corner.
