Updated on 2026-09-24 GMT+08:00

Purchasing DBSS

Scenario

Database audit is deployed in out-of-path pattern. It supports audit of RDS databases and databases built on ECS and BMS on Huawei Cloud.

DBSS can be purchased in yearly/monthly mode. Security audit provides the starter, basic, professional, and advanced editions. You can purchase DBSS edition as needed. For details, see Purchasing DBSS.

Notes and Constraints

  • DBSS cannot be used across regions and the database must be in the same region as the instance you purchased.
  • Ensure the VPC of the database audit instance is the same as that of the node (application side or database side) where you plan to install the database audit agent. Otherwise, the instance will be unable to connect to the agent or perform audit. For details about how to create a shared VPC, see Shared VPC.
  • For details about how to choose the node, see How Do I Determine Where to Install an Agent?
  • To purchase an encryption or O&M instance, submit a service ticket.

Impact on the System

DBSS works in out-of-path mode, which neither affects user services nor conflicts with the local audit tools.

Prerequisites

Check whether the instance account has the required permissions. For details, see DBSS Permission Management.

Ensure that the DBSS System Administrator, VPC Administrator, ECS Administrator, and DBSS Administrator policies have been configured for the account used for purchasing instances.

  • VPC Administrator: Users with this role can perform any operations on the VPC. It is a project-level role, which must be assigned in the same project.
  • DBSS Administrator: Users with this set of permissions can perform any operation on menu items on pages My Account, Billing Center, and Resource Center. It is a project-level role, which must be assigned in the same project.
  • ECS Administrator: Users with this role can perform any operations on an ECS. It is a project-level role, which must be assigned in the same project.

Purchasing DBSS

  1. Log in to the DBSS console.
  2. Click in the upper left corner on the displayed page and select a region.
  3. In the upper right corner, click Buy DBSS.
  4. On the DBSS purchase page, complete the following configurations.

    Table 1 Database audit parameters

    Parameter

    Description

    Basic Settings

    Service Type

    Select a service type. Only Database Audit Service is supported currently.

    Billing Mode

    Select a billing mode for the instance. Currently, only Yearly/Monthly is available.

    Region

    Select the region where the database audit instance is located. For details, see Selecting a Region.

    AZ Type

    Select an AZ type. Only General is supported.

    AZ

    Select an AZ. For details, see Selecting an AZ

    Edition Configuration

    Edition

    DBAS provides four editions: starter, basic, professional, and advanced. For details, see Edition Differences.

    Network Configuration

    VPC

    You can select an existing VPC, or click View VPC to create one on the VPC console.

    NOTE:
    • Select the VPC of the node (application or database side) where you plan to install the agent. For more information, see How Do I Determine Where to Install an Agent?
    • To change the VPC of a DBSS instance, unsubscribe from it and purchase a new one.

    For more information about VPC, see Virtual Private Cloud User Guide.

    Subnet

    You can select a subnet configured in the VPC or create a subnet on the VPC console.

    Security Group

    You can select an existing security group in the region or create a security group on the VPC console. Once a security group is selected for an instance, the instance is protected by the access rules of this security group.

    For more information about security groups, see Virtual Private Cloud User Guide.

    Advanced Settings

    Name

    You can enter a custom instance name.

    The name can contain a maximum of 64 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

    Remarks (Optional)

    You can add instance remarks.

    The remarks can contain a maximum of 225 characters. Only letters, digits, spaces, underscores (_), and hyphens (-) are allowed.

    Enterprise Project

    This parameter is provided for enterprise users.

    An enterprise project groups cloud resources, so you can manage resources and members by project. The default project is default.

    Select an enterprise project from the drop-down list. For more information about enterprise projects, see Enterprise Management User Guide.

    Tag

    (Optional) Identifier of the database audit instance. Adding tags helps you better identify and manage your database instances. A maximum of 50 tags for each instance

    If you have configured tag policies for DBSS, you need to add tags to your DBSS instances based on the tag policies. If you add a tag that does not comply with the tag policies, the database audit instance may fail to be created. Contact your organization administrator to learn more about tag policies.

    Required Duration

    Select a required duration for the instance.

    You can purchase DBSS by month or year.

    Auto-renew

    After you select Auto-renew, the system automatically renews the instance upon expiry if your account balance is sufficient. You can continue to use the instance. Table 2 describes the auto-renewal period.

    Table 2 Auto-renewal period description

    Required Duration

    Auto-renewal Period

    1/2/3/4/5/6/7/8/9 months

    1 month

    1/2/3 years

    1 year

  5. Confirm the configuration and click Next.

    For any doubts about the pricing, click Pricing details to understand more.

  6. On the Details page, read the Database Security Service Statement, select I have read and agree to the Database Security Service Statement, and click Submit.
  7. On the displayed page, select a payment method.
  8. After you pay for your order, you can view the creation status of your instances.

Follow-Up Procedure

  1. Log in to the DBSS console.
  2. Click in the upper left corner on the displayed page and select a region.
  3. In the navigation tree on the left, choose Instances.
  4. Check the instance status.

    • If the Status of the instance is Running, you have successfully purchased the database audit instance.
    • If the instance status is Creation failed, you will be automatically refunded. You can click More in the Operation column and view details in the Failure Details dialog box.

References

For more information about purchase, renewal, and unsubscription, see Purchase, Renewal, and Unsubscription.