Updated on 2023-01-10 GMT+08:00

Quick Start

After applying for a database audit instance, add the database to be audited to the instance and install an agent on the database or application side. Database audit works only when the database to be audited is connected to the database audit instance.

Background

Database audit supports auditing databases built on ECS, BMS, and RDS on the management console.

  • Ensure the VPC, security group, and subnet of the database audit instance are the same as those of the node (application side or database side) where you plan to install the database audit agent. Otherwise, the instance will be unable to connect to the agent or perform audit.
  • If SSL is enabled for a database, the database cannot be audited. To use database audit, disable SSL first.

Quick Configuration Procedure

After purchasing database audit, you can quickly get started by following the configuration procedure shown in Figure 1. For details, see Table 1.

Figure 1 Procedure for quickly configuring database audit
Table 1 Procedure for quickly configuring database audit

Step

Configuration

Description

1

Adding a Database

Apply for database audit. Add a database to the database audit instance and enable audit for the database.

2

Adding an Agent

Select an agent add mode.

Database audit supports auditing databases built on ECS, BMS, and RDS on the cloud. Select an agent add mode based on your database deployed on the management console.

3

Adding Security Group Rules

Configure TCP (port 8000) and UDP (ports 7000 to 7100) in the security group inbound rule of the database audit instance to allow the agent to communicate with the audit instance.

4

Installing an Agent (Linux OS)

Download and then install the agent on the database or application based on the add mode you chose.

5

Enabling Database Audit

Enable database audit and connect the added database to the database audit instance.

6

Viewing the Audit Results

By default, database audit complies with a full audit rule, which is used to audit all databases that are connected to the database audit instance. You can view the audit result on the database audit page.

Verifying the Result

When you connect the added database to the database audit instance, database audit records all operations performed on the database. You can view the audit result on the database audit page.