Microsoft SQL

Version: Microsoft SQL Server 2012 or later.

Microsoft SQL Server is a relational database management system with several features and services. With this coverage, there is a large surface area for attack and vulnerabilities. Netsurion Open XDR utilizes both server audit specifications and extended events to:

  • Address requirements for compliance
  • Analyze database actions to troubleshooting problems
  • Investigate suspicious user activity

Netsurion Open XDR MS SQL reports provide information about database activities. By using these reports, we can examine user login success and login failures for further investigation, the reports can track the database changes in the tables, views, procedures, triggers, schema and track any SQL query errors.

Dashboards display a graphical representation of the database object changes and actions carried out on that object.

Through dashboards, we can also easily track multiple/brute force login failures. Alerts trigger when a user performs any changes on the database, database view, schema, user management, etc.

  • Security – User activities, extended event session management, SQL error events
  • Operations – DDL changes in database, trigger, view, index, and schema
  • Compliance – Password change events, user logon events, and permission to change events.

After Microsoft SQL Server is configured to deliver events to Netsurion Open XDR, alerts, dashboards, and reports can be configured into Netsurion Open XDR.

To take advantage of this data source integration and to learn more about alerts, reports, and dashboards, contact your Technical Account Manager (TAM). If you are not currently a Netsurion customer or partner, contact us to learn more.