Alarm Management
When a system or service alarm is generated from the DBSS service, the alarm is pushed to the DSC in real time. Users can check and handle the alarm. Alarms are stored in the DSC for 30 days.
Prerequisites
The DBSS service has been enabled and there are available assets on it. For details, see Purchasing Database Audit.
Viewing the Alarm Management List
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - In the navigation tree on the left, choose .
- You can view the unhandled alarms, alarm sources, and total number of alarms. Figure 1 Alarm doughnut chart
- View the alarm list. For details about the parameters, see Table 1.
Table 1 Data risk alarm parameters Parameter
Description
Alarm Name/ID
Indicates the name of the alarm source. An alarm should denote the content of the alarm. You can click an alarm name to view details about the alarm, including basic alarm information, handling suggestions, and attack information.
Alarm Severity
There are five alarm severities:
- Suggestion
- Low
- Medium
- High
- Critical
Subcategory/Category
Alarm source types:
- Database attacks
Source
Database audit, database security gateway and instance names.
Client IP
IP address where the alarm is triggered.
Status
The status options are:
- Open
- Blocked
- Closed
Affected Assets
Affected databases
Verification Status
Its value can be:
- Unknown
- Confirmed
- False
Owner
Username.
Created
Time the alarm was created.
Occurred On
Time when an alarm occurs for the first time.
Converting DBSS Alarms to Events
- Log in to the DSC console.
- In the navigation tree on the left, choose .
- Click Convert to Event in the Operation column of the alarm list. The Convert to Event page is displayed.
- Set the parameters by referring to Table 2.
- Click OK to convert an alarm to an event. You can view the converted event on the Event Management page.
Related Operations
- Disabling an alarm: Locate the alarm and click Stop in the Operation column.
- Editing an alarm: Locate the alarm and choose in the Operation column.
- Deleting an alarm: Locate the alarm and choose in the Operation column.
Deleted data cannot be restored. Exercise caution.
References
- Event management: After an alarm is converted to an event, you can view it on the event management page.
- For details about database audit, see Database Audit.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot