Académique Documents
Professionnel Documents
Culture Documents
Note: You can receive event data from more than one database by configuring and
enabling multiple database plugins (one database per plugin).
Sample Database Plugin Configuration File
Following sections included here describe the operation of various sections of the
sample plugin configuration file.
How to Create a Start Query for the Microsoft SQL Server Database
The following code example initiates a query for the Microsoft SQL Server database.
[start_query]
query="SELECT TOP 1 AutoID FROM EPOEvents ORDER BY AutoID DESC"
The duration between queries depends on the setting of each plugin's configuration
file, which reads the value of sleep in the file. Default settings may range from two to
60 seconds and are user-configurable. For information about customizing existing or
developing new plugins, see Customizing and Developing New Plugins and its related
topics.
This query starts with query and also references the "start query" code line, shown
in boldface type in the following example.
[query]
query="SELECT AutoID, CONVERT(nvarchar(40), AutoGUID), ServerID,
DetectedUTC, SourceIPV4, TargetIPV4, TargetUserName, TargetFileName,
ThreatCategory, ThreatEventID, ThreatSeverity, ThreatName FROM
EPOEvents where AutoID > $1 ORDER BY AutoID"
regexp=
Important: You must leave the regexp field empty (shown below the query), because
database plugins use it in operation.
... """"
username={$6}
userdata1=GUID {$2}
userdata2=ServerID {$2}
userdata3=Severity {$10}
userdata4={$9}
userdata5={$11}
userdata6={$1}
Important: You need to repeat this task for every external database you want to
receive data from.
To configure communication with an external database
Field Description
Referencia: https://www.alienvault.com/documentation/usm-appliance/plugin-
management/configuring-database-plugins.htm