Overview
This article contains the steps for the following:
- Creating a new Microsoft® SQL Server® group.
- Adding a new Microsoft® SQL Server® event source.
Process
Creating a new Microsoft® SQL Server® group
To create a Microsoft SQL Server group:
- Click the Configuration tab > Event Sources.
- From Group Type, select Database Servers Groups.
- From Groups, right-click Microsoft SQL Server and select Create group...
- Select Microsoft SQL Server as the server type and from the General tab configure the options accordingly.
Option Description Group Name Key in a group name to identify the Microsoft SQL Server group. Description (Optional) Key in a description. Collects logs from the database servers included in this group Enable this option to collect database events from all servers in this group. - Select the Logon Credentials tab and configure the options accordingly.
Option Description Use Windows authentication Connect to the Microsoft SQL Database using windows authentication. Use SQL Server authentication Connect to Microsoft SQL Database using a Microsoft SQL Database user account. Key in a username and password.
- Select Operational Time and configure the operational time when the database is normally used. Marked time intervals are considered normal working hours.
- Select the SQL Server Audit tab and configure the options accordingly.
Option Description Archive all logs without further processing Archive events in GFI EventsManager database backend without applying processing rules. Process the logs with the rules selected below before archiving Specify the rules to perform before archiving events in GFI EventsManager database backend.
- Select the Settings tab and configure the options accordingly.
Option Description Scan all the events for all databases All Microsoft SQL Server events are collected and processed by GFI EventsManager. Scan only security events for all databases Only security events are collected and processed by GFI EventsManager.
- Click Apply and OK.
Adding a new Microsoft® SQL Server® event source
To add a new Microsoft SQL Server source:
- Right-click a database group and select Add new SQL Server®...
- Key in the server name or IP and click Add.
- Click Finish and the Add New SQL Servers... dialog closes.
- From Groups, select SQL Servers and from the right pane, double-click the new Microsoft SQL Database instance.
Note: Use Select and Import to search the network for SQL Server or import list of SQL servers from a text file respectively. - From the General tab, configure the options accordingly.
Option Description Inherit SQL Server post collecting processing from parent group Inherits all settings from the parent group. Archive events in database Archive events in GFI EventsManager database backend without applying processing rules. Process using these rule sets Specify the rules to perform before archiving events in GFI EventsManager database backend.
- Select Connection Settings and configure the options accordingly.
Option Description Inherit the logon credentials from the parent group Select this option to inherit login settings from the parent group. Use Windows authentication Connect to Microsoft SQL Database using windows authentication. Use SQL Server credentials Connect to Microsoft SQL Database using a Microsoft SQL Database user account. Key in a username and password.
- Select the Settings tab and configure the options accordingly.
Option Description Inherit the settings from the parent group Inherits settings from the parent group. Scan all the events for all databases Scan all databases and collect all events from the Microsoft SQL Server. Scan only the security events for all databases Scan all databases and collect only security events from the Microsoft SQL Server. Scan all the events that are related to the following databases only Collect all events from the selected databases. Use Add, Edit and Remove to manage database sources.
- Click Apply and OK.