tencent cloud

Feedback

Creating Rule Template

Last updated: 2023-12-06 15:09:10
    This document describes how to create a rule template in the console.
    Note
    Starting from September 202325, the relationship between rule templates and audit instances has transitioned from initialization to strong association. Alterations to the rule template content will synchronously impact the audit rules applied to the instances bound to the said rule template.
    A rule template allows up to 5 characteristic strings for a single parameter field, with each string being separated by vertical bar "|".

    Directions

    1. Log in to the TencentDB for MySQL console.
    2. On the left sidebar, click Database Audit.
    3. Select Region and click Rule Template.
    4. In the template list, click Create Rule Template.
    
    5. In the Create Rule Template window, set the following configuration items and click OK.
    
    Parameter
    Description
    Rule Template Name
    This field can contain up to 30 letters, digits, and symbols -_./()[]()+=::@ and cannot start with a digit.
    Rule Content
    This fields sets the rule content (parameter field, operator, characteristic string). For detailed instructions, see the Rule content details and examples.
    Note
    Under the section of rule content, one can augment parameter fields by clicking on 'Add'.
    Within the operation column under the rule content, unnecessary parameter fields and conditions can be eliminated by clicking 'Delete'. However, at least one parameter field and condition must be retained.
    
    Risk Level
    Select a risk level for the newly created rule template, with options including low risk, medium risk, and high risk.
    Alarm Policy
    Choose an alarm policy for the newly created rule template, with options of either refraining from sending alarms or sending alarms.
    Note:
    Please go to TCOP->Alarm Management to set alarm rules and notifications. For detailed information, refer to Post-Event Alarm Configuration.
    
    Rule Template Remarks
    This field can contain up to 200 letters, digits, and symbols-_./()[]()+=::@ and cannot start with a digit.

    Rule content details and examples

    Note
    You can configure one or multiple rules. Up to 5 rules can be configured.
    Different rules are in AND relationship; that is, they need to be met at the same time.
    Different characteristic strings in a rule are in OR relationship; that is, at least one of them needs to be met.
    You can add only one operator for the same parameter field; for example, for the database name, the operator can be either Include or Exclude.
    Parameter Field
    Operator
    Characteristic String
    Client IP
    Include, Exclude, Equal to, Not equal to, Regex
    Up to five client IPs can be configured and should be separated by vertical bar "|". When the operator is Regex, only one characteristic string can be entered.
    Username
    Include, Exclude, Equal to, Not equal to, Regex
    Up to five usernames can be configured and should be separated by vertical bar "|". When the operator is Regex, only one characteristic string can be entered.
    Database Name
    Include, Exclude, Equal to, Not equal to, Regex
    Up to five database names can be configured and should be separated by vertical bar "|". When the operator is Regex, only one characteristic string can be entered.
    SQL Details
    Include, Exclude
    Up to five SQL commands can be configured and should be separated by vertical bar "|". When the operator is Regex, only one characteristic string can be entered.
    SQL Type
    Equal to, Not equal to
    Up to five SQL types can be selected. Valid options: ALTER, CHANGEUSER, CREATE, DELETE, DROP, EXECUTE, INSERT, LOGIN, LOGOUT, OTHER, REPLACE, SELECT, SET, UPDATE.
    Affected Rows
    Greater than, Less than
    Select affected rows
    Returned Rows
    Greater than, Less than
    Select returned rows
    Scanned Rows
    Greater than, Less than
    Select scanned rows
    Execution Time
    Greater than, Less than
    Select execution time in microseconds
    Example: If the following rule content is set, the database name should include a, b, or c, and the client IP should include IP1, 2 or 3, then the audit logs filtered by the rule are those where the database name includes a, b, or c and the client IP includes IP1, 2, or 3.
    
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support