Live operational auditing for SQL Server from a single desktop. See every login, DDL change, permission grant and backup across all your instances in near-real time — with AI-powered insights, SIEM integration, and alerts. Add the optional Compliance Pack to read from a native SQL Server Audit for SOX, HIPAA, PCI DSS and GDPR evidence trails.
Auditing SQL Server for regulatory and organizational compliance is challenging — complex database environments, multiple users with varying permissions, frequent changes, and evolving compliance standards. DBLense SQL Auditor reduces the time and effort required to configure, monitor, and report on compliance from days to minutes.
All audit data from every monitored SQL Server instance flows into a single centralized database. Role-based access (Admin, Operator, Viewer) ensures the right people see the right data.
A lightweight Windows service runs 24/7, continuously collecting audit events from each registered instance with minimal overhead and no gaps in coverage.
A streamlined desktop application with five tabs — Dashboard, Events, Configure, Alerts, and Reports — plus a dedicated Settings window for service management, user administration, integrations, and security.
Built-in AI analysis panel that provides automated security summaries, anomaly detection, threat analysis, and actionable recommendations — all from a slide-out drawer without leaving your workflow.
Forward alerts to Splunk, Microsoft Sentinel, Elastic, Slack, Teams, PagerDuty and more. Supports JSON and CEF formats with automatic retries and health monitoring per endpoint.
Enable the Compliance Pack to read directly from a native SQL Server Audit you configure on the monitored instance (on-prem TO FILE or Azure Managed Instance TO URL). The collector reads via sys.fn_get_audit_file() over the same TCP 1433 connection — no agent, no file share, no Azure SDK. Produces the tamper-evident evidence trail auditors recognise for SOX, HIPAA, PCI DSS.
Generate PDF compliance reports with a single click — Sensitive Data Access, Permission Changes, Schema Changes, and Failed Logins. Configurable report periods for audit reviews.
Automatic alerts with severity levels (Critical, Warning, Info), acknowledgment tracking, and badge counts. Alert on failed logins, privilege escalations, schema changes, and more.
Pre-configured audit policies aligned with major regulatory frameworks. Each compliance pack covers the event categories, report types, and alert rules needed to satisfy specific requirements. For audit evidence trails accepted by external auditors, combine with the optional Compliance Pack (SQL Server Audit integration) described below.
General Data Protection Regulation. Track who accessed or modified personal data, with full login and timestamp accountability for data subject access requests.
Health Insurance Portability and Accountability Act. Maintain audit trails for patient record access with tamper-proof evidence and automatic alerts for unauthorized access.
Sarbanes-Oxley Act. Monitor privilege changes and administrative actions for financial data integrity. Track role changes, permission grants, and configuration modifications.
Payment Card Industry Data Security Standard. Detect unauthorized access attempts, track authentication activity, and monitor cardholder data environments with configurable retention.
Configure per-instance audit policies with granular control over what gets tracked. Choose from pre-built categories or customize your own.
Go beyond raw event logs. The built-in AI panel analyzes your audit data and surfaces actionable intelligence.
High-level overview of your audit posture with key metrics and risk indicators.
Identify unusual patterns — off-hours access, bulk data operations, and privilege escalations.
Assess brute-force attempts, suspicious schema changes, and potential data exfiltration.
Actionable hardening suggestions based on your specific audit data and environment.
Raise alerts when potential compliance issues arise. Send notifications to your existing tools via webhook and SIEM integration.
An optional, drop-in upgrade that reads security and backup events from a native SQL Server Audit you configure on the monitored instance. This is the evidence trail external auditors recognise for SOX, HIPAA, PCI DSS and ISO 27001 — produced by SQL Server itself and tamper-evident by design.
SERVER AUDIT with the action groups DBLense recognises (logins, principals, roles, permissions, backup/restore, audit changes)..sqlaudit files (path you choose, e.g. C:\SQLAudit\)..xel files to an Azure Blob container via SAS credential.sys.fn_get_audit_file() over the same TCP 1433 connection it already uses — SQL Server reads the file or blob on our behalf.sqlcmd -I -i install-server-audit-*.sqlFull walkthrough, tuning, cost notes, and troubleshooting: Compliance Pack setup guide.
When the Compliance Pack is on, the collector records the source audit GUID and file/blob URI of every event it imports. Reports cite these back to SQL Server's own audit trail so reviewers can verify the chain — no “trust us” required.
.sqlaudit / .xel fileGenerate polished PDF reports with a single click for internal reviews or external audits. Four pre-built report types aligned with common compliance requirements.
Monitor every login, schema change, and permission modification across all your SQL Server instances in near-real time. Add the optional Compliance Pack to layer in a tamper-evident SQL Server Audit trail for SOX, HIPAA, PCI DSS and GDPR evidence — all from a single desktop.