Common Workflows

Enable audit for a database

  1. Open Configure Audit; select the instance/database.
  2. Choose event categories (logins, DDL, permission changes, data access as needed).
  3. Apply filters to reduce noise; save and confirm the collector is running.
  4. Generate a test event and verify it on the Events tab.

Security incident review

  1. Filter Events by time, login, and success/failure.
  2. Open related alerts; export for IR tickets.
  3. Use Compliance Reports for control evidence (SOX/HIPAA/PCI mappings where configured).