Updated on 2026-08-19 GMT+08:00

Alarm Management

When a system or service alarm is generated from the DBSS service, the alarm is pushed to the DSC in real time. Users can check and handle the alarm. Alarms are stored in the DSC for 30 days.

Prerequisites

The DBSS service has been enabled and there are available assets on it. For details, see Purchasing Database Audit.

Viewing the Alarm Management List

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation tree on the left, choose Data Security Operations > Alarms.
  4. You can view the unhandled alarms, alarm sources, and total number of alarms.

    Figure 1 Alarm doughnut chart

  5. View the alarm list. For details about the parameters, see Table 1.

    Table 1 Data risk alarm parameters

    Parameter

    Description

    Alarm Name/ID

    Indicates the name of the alarm source. An alarm should denote the content of the alarm. You can click an alarm name to view details about the alarm, including basic alarm information, handling suggestions, and attack information.

    Alarm Severity

    There are five alarm severities:

    • Suggestion
    • Low
    • Medium
    • High
    • Critical

    Subcategory/Category

    Alarm source types:

    • Database attacks

    Source

    Database audit, database security gateway and instance names.

    Client IP

    IP address where the alarm is triggered.

    Status

    The status options are:

    • Open
    • Blocked
    • Closed

    Affected Assets

    Affected databases

    Verification Status

    Its value can be:

    • Unknown
    • Confirmed
    • False

    Owner

    Username.

    Created

    Time the alarm was created.

    Occurred On

    Time when an alarm occurs for the first time.

Converting DBSS Alarms to Events

  1. Log in to the DSC console.
  2. In the navigation tree on the left, choose Data Security Operations > Alarms.
  3. Click Convert to Event in the Operation column of the alarm list. The Convert to Event page is displayed.
  4. Set the parameters by referring to Table 2.

    Table 2 Parameters for converting an alarm to an event

    Parameter

    Description

    Event Name

    Enter the event name.

    Event Type

    Select an event type from the drop-down list box.

    Planned Closure Time

    Select the time when the event is closed.

  5. Click OK to convert an alarm to an event. You can view the converted event on the Event Management page.

Related Operations

  • Disabling an alarm: Locate the alarm and click Stop in the Operation column.
  • Editing an alarm: Locate the alarm and choose More > Edit in the Operation column.
  • Deleting an alarm: Locate the alarm and choose More > Delete in the Operation column.

    Deleted data cannot be restored. Exercise caution.

References

  • Event management: After an alarm is converted to an event, you can view it on the event management page.
  • For details about database audit, see Database Audit.