The sensitive data audit feature in Data Management (DMS) records every access to sensitive data across your databases, helping you detect abnormal use and investigate data leakages.
How it works
DMS generates an audit log entry whenever a user performs any of the following operations:
Data query or data change in SQLConsole
Data result set export
Database export
Regular data change
Each audit log entry captures the operator, the involved feature, the time the operation was performed, the database name, the source IP address, and the ticket or task number.
Which entry point to use
DMS provides two places to review sensitive data audit logs:
Sensitive Data Audit page — use this when you want to search and filter audit logs by criteria such as database, table, column, or user.
Operation Logs tab — use this when you are already reviewing general operation logs and want to identify which tickets or tasks involved sensitive data.
View audit logs on the Sensitive Data Audit page
Log on to the DMS console V5.0.
-
Move the pointer over the
icon in the upper-left corner and choose . NoteIf you use the DMS console in normal mode, choose in the top navigation bar.
On the Sensitive Data Audit page, set one or more of the following filter parameters and click Search:
NoteBy default, DMS displays audit logs from the last day.
Parameter Description Function The DMS feature that accessed the sensitive data User name The operator who performed the action Time The time range for the audit logs Database Name The database containing the sensitive data Table name The table containing the sensitive data Column name The column identified as sensitive Optional: Click the
icon before a ticket or task to view its details, including:Names of tables containing sensitive data
Names of sensitive fields
Sensitivity levels
User permissions
Configured de-identification algorithms
View audit logs on the Operation Logs tab
Log on to the DMS console V5.0.
-
Move the pointer over the
icon in the upper-left corner and choose . NoteIf you use the DMS console in normal mode, choose in the top navigation bar.
Click the Operation Logs tab.
In the Ticket/Task column, tickets and tasks that involve sensitive data are labeled Sensitive.
Hover over Sensitive in the Ticket/Task column, then click here in the tooltip that appears. The Details dialog box shows the full breakdown of that ticket or task, including:
Names of tables containing sensitive data
Names of sensitive fields
Sensitivity levels
User permissions
Configured de-identification algorithms