> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# DbProtect  6.7.1

DbProtect is a data security platform for data stores, including relational databases and Big Data. This guide (Version 6.7.1, July 2026) introduces the interface and components within DbProtect and provides the instructions needed to complete administrative and user workflow tasks.

## Formatting Conventions

This manual uses the following formatting conventions to denote specific information.

| Formats and Symbols | Meaning |
| - | - |
| Blue Underline | A blue underline indicates a link to a website or email address. |
| **Bold** | Bold text denotes UI control and names, such as commands, menu items, tab and field names, button and checkbox names, window and dialog box names, and areas of windows or dialog boxes. |
| `Code` | Text in code format indicates computer code or information. |
| *Italics* | Italics denote the name of a published work, the current document, name of another document, text emphasis, to introduce a new term, and path names. |
| \[Square brackets] | Square brackets indicate a placeholder for values and expressions. |

### Notes, Tips, and Cautions

<Note>
  **Note:** This symbol indicates information that applies to the task at hand.
</Note>

<Tip>
  **Tip:** This symbol denotes a suggestion for a better or more productive way to use the product.
</Tip>

<Warning>
  **Caution:** This symbol highlights a warning against using the software in an unintended manner.
</Warning>

## Introduction

DbProtect is a data security platform for data stores, including relational databases and Big Data. Supported databases include on-premises and cloud services. DbProtect uncovers conditions that could lead to escalation of privileges attacks, data leakage, denial-of-service (DoS), or unauthorized modification of data. The conditions checked include database configuration mistakes, identification and access control issues, missing patches, and other settings.

DbProtect provides multi-user/role-based access, highly scalable distributed architecture, and enterprise level analytics. DbProtect enables organizations to secure their relational databases, document databases and Big Data stores throughout their environment, on premises or in the cloud.

This guide introduces the interface and components within DbProtect.

### Document Audience

This guide is intended for personnel using DbProtect on a day-to-day basis. It provides the detailed instructions necessary to complete all administrative and user workflow tasks. This guide does not include instructions for the installation or upgrade of the software components, licensing, network access, or the setup and configuration of databases.

System Administrators: refer to the *DbProtect Install and Upgrade Guide* for detailed instructions on how to install/upgrade DbProtect and prepare it for use on your network.

If DbProtect installation and setup have been completed by LevelBlue personnel, refer to your organization's *DbProtect Run Book* for customized day-to-day operational procedures developed and documented specifically for your organization.

<Note>
  **Note:** Customized *DbProtect Run Books* are developed for customers as part of a paid Consulting & Professional Services engagement. Please contact your Account Manager or your LevelBlue Sales Professional for more information.
</Note>

# DbProtect Components

A DbProtect installation includes a console server and one or more scan engines. DbProtect has two interfaces: DbProtect Core (legacy) and DbProtect Explorer (new).

#### Scan Engines

DbProtect vulnerability management scan engines discover databases within your infrastructure and assess their security strength. Backed by a proven security methodology and extensive knowledge of application-level vulnerabilities, DbProtect locates, examines, reports, and helps users operationalize security holes and misconfigurations. Scan engines scan your database instances for vulnerabilities and allow you to perform Pen Tests and Audits against them.

#### Sensors

Sensors deliver database-specific monitoring and alerting for best-in-class protection of enterprise organizations. You can fine-tune your event detection parameters and customize which audit and security events are monitored by DbProtect. This helps you focus security efforts on relevant information, while bypassing false positive and irrelevant events.

#### DbProtect Core

DbProtect Core is a web-based application facilitating navigation across various features, offering essential services for scanning, reporting, and data warehousing management.

<img src="https://mintcdn.com/levelblue-5324744e/KdaRYLBoJ2Djt8-0/images/Db1.jpg?fit=max&auto=format&n=KdaRYLBoJ2Djt8-0&q=85&s=42f12d155ff6dbc50a93cf69690308de" alt="Db1" width="975" height="662" data-path="images/Db1.jpg" />

For more information about the DbProtect Core, see [Familiarize yourself with DbProtect](#familiarize-yourself-with-dbprotect).

#### DbProtect Explorer

The DbProtect Explorer sits on top of all your existing and ongoing DbProtect data and settings. DbProtect Core and DbProtect Explorer users will see and access the same data, and activities performed in one console are reflected in the other. Although the DbProtect Explorer user interface currently applies only to the Dashboard, Alerts, and Exploration components in the release, all the existing components of DbProtect Core are available through links in the navigation pane on the left side of the DbProtect Explorer.

<img src="https://mintcdn.com/levelblue-5324744e/KdaRYLBoJ2Djt8-0/images/db2.jpg?fit=max&auto=format&n=KdaRYLBoJ2Djt8-0&q=85&s=d6f93ddf626e5872dc67aab521e4f73e" alt="Db2" width="973" height="832" data-path="images/db2.jpg" />

We welcome your input into future development and encourage you to contact [LevelBlue Support](https://www.levelblue.com/company/support) with all questions and feedback about the new Explorer.

See [Navigating in DbProtect Explorer](#navigating-in-dbprotect-explorer) for instructions for accessing and using the Explorer.

### Use Single Sign-on (SSO) to access DbProtect

For single sign-on (SSO) to function properly, you may need to configure your browser by adding the DbProtect URL to your list of trusted intranet sites.

<Tip>
  **Tip:** Refer to the instructions for your specific web browser and version to add the following to your list of trusted intranet sites.

  `https://[dbprotecturl]`

  (where `[dbprotecturl]` is the DbProtect console URL)
</Tip>

# Permissions and Prerequisites

To use DbProtect successfully, you must allow specific network access and user permissions.

### Network Access for DbProtect Components

DbProtect components communicate on the network ports listed in the table below. For full details of required access, see the *DbProtect Installation Guide and Getting Started Guide*.

| Component | Default Listening Port | Type | Purpose |
| - | - | - | - |
| Console | 20080<br />20081 | TCP | Console browser connections<br />Receives Activity Monitoring Alerts/Events from Sensors. Used by Message Collector |
| Explorer | 20082<br />20083 | TCP | Explorer Authentication Service<br />Explorer Interface |
| SQL Service Repository | As configured | TCP | Verify this port assignment with the SQL Server Administrator |
| Sensor | 20000 | TCP | Console communication with sensor |

### User Permissions and Network Access for Target Assets

DbProtect scanning and auditing jobs require specific access to the Operating Systems and databases scanned. A summary of the requirements is included in [Appendix B: User Account Privileges Needed for Audit and User Rights Review Scans](#appendix-b-user-account-privileges-needed-for-audit-and-user-rights-review-scans). For the latest information about required access (including scripts to set required values), see the Readme file installed with the current SHATTER Knowledgebase. You can find the Readme file in the File Cabinet portal.

DbProtect installs by default in the following location:

```text theme={null}
C:\Trustwave\DbProtect\
```

The User Creation Scripts and Readme are in the subfolder:

```text theme={null}
..\Resources\ShatterKnowledgebase\UserCreationScripts\
```

### Log in to DbProtect Core

To use a browser to connect to DbProtect Core:

1. Enter `https://[ConsoleServer]:[Port]` in the address line, where:
   * `[ConsoleServer]` is the hostname or IP Address of DbProtect Core server
   * `[Port]` is the port number where DbProtect Core Management Server has been configured to provide service. The default port as installed is 20080 (e.g., `https://DbProtect_server:20080`).
2. A Security Alert message may be displayed, warning you of an invalid security certificate. You can safely continue past this message. DbProtect uses a self-generated SSL certificate by default to encrypt communications.
   <img src="https://mintcdn.com/levelblue-5324744e/KdaRYLBoJ2Djt8-0/images/db3.jpg?fit=max&auto=format&n=KdaRYLBoJ2Djt8-0&q=85&s=7512a5895d27188b70ecd777214c66b8" alt="Db3" width="933" height="527" data-path="images/db3.jpg" />
   <Warning>
     **Caution:** DbProtect is designed to use only Transport Layer Security (TLS) communication, which encrypts your username and credentials prior to transmission to DbProtect. DbProtect then uses the Windows Authentication subsystem to verify the credentials. For information about how to generate and install a valid certificate, please contact LevelBlue Product Support
   </Warning>
3. From the Log In menu, select Use **Windows Authentication** or **Manually**.
   * If you select **Use Windows Authentication**, DbProtect uses your Windows login credentials to log on to DbProtect.
   * If you select **Manually**, you are prompted to enter your login credentials.
4. In the **Username** field, enter your DbProtect username. You can also enter the domain information in this field in usual Windows formats such as `domain\username`.
5. In the **Password** field, enter the password that matches the username.
6. Use the **Domain** menu to select the domain for the username or manually enter a domain in this field.
7. Click **Log In**. If the credentials you entered are valid, DbProtect Core opens.

### DbProtect Explorer

The DbProtect Explorer sits on top of all your existing and ongoing DbProtect data and settings. DbProtect Core and DbProtect Explorer users will see and access the same data, and activities performed in one console are reflected in the other. Although the DbProtect Explorer user interface currently applies only to the Dashboard, Alerts, and Exploration components in the release, all the existing components of DbProtect Core are available through links in the navigation pane on the left side of the DbProtect Explorer.

<img src="https://mintcdn.com/levelblue-5324744e/KdaRYLBoJ2Djt8-0/images/db2.jpg?fit=max&auto=format&n=KdaRYLBoJ2Djt8-0&q=85&s=d6f93ddf626e5872dc67aab521e4f73e" alt="Db2" width="973" height="832" data-path="images/db2.jpg" />

See [Navigating in DbProtect Explorer](#navigating-in-dbprotect-explorer) for instructions for accessing and using the Explorer.

### Troubleshooting Your DbProtect Core Login

If you have trouble logging on to the DbProtect Core, you may need to troubleshoot your security settings or change your browser configuration.

* In **Control Panel** | **Internet Options** | **Advanced**, if **Integrated Windows Authentication** is enabled the Windows user will be automatically authenticated, if possible, in modern browsers that are configured properly.
* Ensure that JavaScript is enabled in the browser.
* DbProtect Core provides basic functionality in current versions of major browsers. You may see slight variations in the presentation of pages between browsers.
* When there is no activity on your machine for a specified period of time, you will be logged out. You must log in again by returning to the Login screen.

## Familiarize yourself with DbProtect

DbProtect Core is the primary user interface for DbProtect.

### Navigating DbProtect Core

For a typical view of the basic DbProtect Core screen layout, see [DbProtect Core](#dbprotect-core).

The upper right portion of the screen shows the Account ID of the logged-in user, Help and New Feature information, and the Log Out link.

Many panes of the console show data in lists. Common tools for list views include:

| Feature | Function | | |
| - | - | - | - |
| Change Organization | Change Organization | | |
| Refresh | Refresh the list in any tab by clicking **Refresh** | | |
| Auto-Refresh | Click to enable or disable Auto-Refresh of the list | | |
| Expand/Collapse all | For views with a hierarchy, expand or collapse all descendants. | | |
| Column headings | Click any column heading to sort.<br />Click the down arrow at the right of any column header to:<br />• Sort ascending or descending<br />• Show or hide columns<br />• Filter by text in any column | | |
| Pane divider | For views with a top and bottom pane, place the cursor over the space between panes. When the pointer displays as shown, click and drag to change the amount of space used by each pane. | | |
| Paging controls | For lists with many entries, move through multiple pages of the list, and adjust the number of items on each page. If the selected number of items does not fit in the pane, scroll through items using the scroll bar at the right side of the pane. | | |

### Select an organization

In several locations throughout DbProtect Core, the data displayed is based on the specific organization selected at the top right of the content pane.

**To change the organization:**

1. Click **Change Organization**. The Report Viewing Organization Selector dialog opens.
2. Click the expand or collapse controls to expand or collapse the tree view of descendant organizations.
3. Select an **Organization**. For reports, you can choose to include all descendant organizations of the selected organization.
4. Choose to apply the selection to reporting, or only to the part of DbProtect Core where you opened this window.
5. Click **OK** to apply your selections.

### Pages in DbProtect Core

The DbProtect Core taskbar on the upper part of the page allows you to access all the functions of DbProtect Core through "pages." Depending on the permissions of the currently logged-in user, and your organization's specific licensing, some pages may not display.

#### Assets

The **Assets** section of DbProtect Core allows you to create, view, and manage assets in the DbProtect repository. Assets include scannable database instances, and redirectors. You can add database instance entries manually, import entries from a file, and edit existing entries. You can also search the list of known assets by criteria such as database type and network location.

* To scan for database instances and add them to the asset list automatically, use a **Discovery Job** (see [Add assets](#add-assets) for more information).

<Note>
  **Note:** User access to add, view, and manage assets depends on the user's role (permissions) for the DbProtect Core application, and for the organization that an asset is associated with.
</Note>

<img src="https://mintcdn.com/levelblue-5324744e/KdaRYLBoJ2Djt8-0/images/db4.jpg?fit=max&auto=format&n=KdaRYLBoJ2Djt8-0&q=85&s=ab1aa9492b27d7382f74d6a2be8db699" alt="Db4" width="980" height="664" data-path="images/db4.jpg" />

* By default, the asset list only shows scannable assets. Click the **View** menu at the top right of the **Asset Search Results** pane to see all assets.
* Sort and filter the list using standard tools (see [Navigating DbProtect Core](#navigating-dbprotect-core)).
* Search for specific assets (see [Search assets](#search-assets) for more information).

#### Monitoring

The **Monitoring** page allows you to edit monitoring policies for databases and set up real-time monitoring and alerting based on those policies. For more information, see [Set up basic monitoring](#set-up-basic-monitoring).

<img src="https://mintcdn.com/levelblue-5324744e/KdaRYLBoJ2Djt8-0/images/Db5.jpg?fit=max&auto=format&n=KdaRYLBoJ2Djt8-0&q=85&s=84a3c1f71d31f4593c205a5c1c6b0ccf" alt="Db5" width="627" height="274" data-path="images/Db5.jpg" />

<Note>
  **Note:** User access to set up monitoring of assets depends on the user's role (permissions) for the DbProtect application, and for the organization that an asset is associated with.
</Note>

* To select the organization you want to work with, click **Change Organization** (top right of the page).
* The **Monitoring** page uses a set of navigation tabs that allow you to configure and review monitoring for the various pages of the DbProtect taskbar.

| Tab | Action |
| - | - |
| Home | Displays a graphical introduction to monitoring setup and workflow and includes quick links for common tasks. |
| Alerts | Displays a list of recent alerts from monitoring and allows you to search and acknowledge alerts. Also provides a listing of archived alerts. |
| Dashboard | Displays a quick overview of sensor health, unacknowledged alerts, and count of informational alerts. |
| Reports | Directs you to the Latest Activity report in the main On Demand Report section of DbProtect Core. |
| Policies | Provides a view of existing Monitoring policies, and allows you to import, export, edit, and deploy policies. |
| Filters | Allows you to add filter rules to refine database monitoring policies. |
| Sensors | Allows you to register and configure monitoring sensors, and to deploy policies in bulk. |
| Monitoring Settings | Allows you to configure email notifications based on Alerts. |

For more information about how to set up monitoring on each of these tabs, see [Advanced Monitoring](#advanced-monitoring).

#### Jobs

The **Jobs** page allows you to create testing and review activities for a database instance or group of instances and run these activities on demand or on a schedule. For more information, see [Jobs workflow](#jobs-workflow).

<Note>
  **Note:** User access to Jobs depends on the user's role (permissions) for the DbProtect application, and for the organization that an asset is associated with.
</Note>

DbProtect provides several job types to schedule tests and review the activities of your databases.

| Job Type | Description |
| - | - |
| Discovery | Discovery actively scans network segments, collecting an inventory of database components. Discovery jobs are useful for collecting a list of databases running on your network, for finding rogue database installations, and for validating existing database inventory data. Running Discovery scans does not consume purchased DbProtect licenses. |
| Pen Test | A Pen Test is an unauthenticated (outside-in) scan of your databases that searches for vulnerabilities and misconfigurations, which can leave your system exposed to attack from an individual who does not have valid credentials to login to the database. Pen Testing requires DbProtect Vulnerability Management licenses. |
| Audit | An Audit (Security Audit) is an authenticated scan that requires an account with read-only privileges. It performs a deep assessment, checking the configuration of your database for known vulnerabilities and configuration issues. Audits require DbProtect Vulnerability Management licenses. |
| Rights Review | A Rights Review is a deep analysis of user and role entitlements on a database. This type of scan analyzes database user and role privileges, to help organizations guard against the possibility of unauthorized access to data. Rights Review scans identify all users with high levels of permissions and any users with access to sensitive database objects. Rights Review requires DbProtect Rights Management licenses. |
| Report | A Report job allow you to generate and distribute one or more reports from a library of common reports available through DbProtect Analytics. Reports can be presented in a variety of formats which can be generated and then distributed on a recurring schedule. |

<Note>
  **Note:** The steps for running jobs differ depending upon the type of job you run, and the type of assets (databases) being scanned.
</Note>

#### Report DbProtect results

The **Reports** section of DbProtect Core allows you to generate, view, save, and schedule detailed information on security metrics, job operations, assets, administration, vulnerabilities, rights, policies and more.

The **Reports** page of DbProtect Core has two sub-sections: **On Demand** and **History**.

<Note>
  **Note:** User access to Reports depends on the user's role (permissions) for the DbProtect application, and for the organization that an asset is associated with.
</Note>

To generate a real-time, built-in report:

1. Click **Reports | Catalog.**
2. Select one of the built-in on-demand reports. A new browser window/tab will open where the generated report will be displayed.

To view a historical report:

1. Click **Reports | History.**
2. Scroll through the list of reports that have already been generated. These are reports that have been run as part of an executed job, whether set up as a one-time or scheduled job.
3. Select the checkbox next to the report that you want to view.
4. Click the PDF document link for the report (right side) and save the report to your computer.
5. Navigate to the file and double-click to open.

#### Users & Orgs

The **Users & Orgs** page is where you create "organization" containers for permission purposes, assign users (or user groups) to those organizations, and associate policies to the organizations. You can assign roles to users to manage user permissions more easily.

##### Organizations tab

Typically, an "organization" is a group of servers that have similar reporting requirements based on geographical location, line of business, database type, regulatory environment, and/or any other segregation of assets required for reporting purposes. **Organizations** can also be used to create a multitenancy configuration, so a single DbProtect Core can serve multiple business entities, while strictly enforcing segregation of duties, assets, access, and results.

The **Organizations** tab shows the following:

* The top pane lists the organizations set up in DbProtect.
* The bottom pane provides details of the organization selected on the top pane, on four tabs:

| Tab | Displays this for the selected organization |
| - | - |
| Details | Description of the organization. |
| Users | All users or groups that have roles in the organization, and the roles for each user. |
| Assets | Assets that have been added to the organization |
| Policies | Policies that have been configured for the organization. |

* Use the paging controls below the list to view more items.
* If an organization has dependents, click the arrow next to the name to expand the dependent list. You can also use the expand and collapse buttons at the top right of the list to view or hide the dependent organizations.

##### Users tab

DbProtect users are imported from Microsoft Active Directory or from the local server where DbProtect Core is installed. Both users and groups can be imported. Users can be granted a set of roles within the product.

All DbProtect functions are restricted by role-based access. Access to each function is controlled by permissions that are granted to the user through a role. The typical users of the product have been separated into two groups: system and organization. These groups mirror the typical scopes of access control in most environments.

The **Users** tab displays the following:

* The top pane lists users and groups. If there are many entries, you can view them using the corresponding navigation arrows below the list.
* The bottom pane lists the roles and effective permissions of the selected user or group.

#### Settings

The **Settings** page (on the right side of the DbProtect taskbar) allows you to review system performance, manage licensing, email settings, and manage scan engine registrations. For more information, see [Modify System Settings](#modify-system-settings).

## Navigating in DbProtect Explorer

All navigation within **DbProtect Explorer** is initiated through the navigation pane on the left side of the browser window.

### Organization Selector

If your company has a hierarchy, and you have been assigned the necessary role to access the various organizations in the hierarchy, the ability to change between **Organizations** will be visible in the top-right of the **DbProtect Explorer** pages.

Select the organization whose data you want to see reflected in the **Dashboard**, **Alerts**, or **Policies** pages. You can move between organizations and levels, as desired to change the data displayed.

### DbProtect Explorer Dashboard

The DbProtect Explorer Dashboard provides different ways to look at your security and risk positions:

* Hover over legend items to highlight specific bars.
* Click the **Legends** slider button to show or hide chart legends.
* Hover over the chart bars or graphs to display data related to the vulnerabilities or alerts.
* Click a bar or graph line to open the item and display the finding's details and set display and filter options for the chart/graph.

| Dashboard Tab | Displays |
| - | - |
| Security | An overview of the organization's database security across several categories such as Overview vulnerabilities, alerts, assets, and privileged users. |
| Risk Overview | A current and historical picture of the Defense in Depth (scanned, and rights reviewed), the Organizational Risk based on findings, and a breakdown of that risk by Severity and Category. |
| Entitlement Exploration | Shows the rights management data through bubble charts, the size of which represents the number of items in each category. Each successive click moves you a level down until you are viewing the raw data. Once there, search the data for specific users, roles, or tables that require protection. Results can be exported in CSV format directly from the **Entitlement Detail** page. |

The **Security Overview** tab of the Dashboard gives you a quick breakdown of alerts and findings activity and risk, exploitable users, and asset categorization, inventory, and scanning coverage. These initial charts offer convenient high-level views of your DbProtect data, with easy access to underlying data.

* **Vulnerabilities & Alerts by categories**: Organized from High to Low risk, these charts allow you to target vulnerability and asset categories that are at highest risk of producing high numbers of findings or alerts. Hover over the bars to see the category name and number of findings or alerts for the category.
* **Vulnerabilities and Alerts over time**: See the trends of findings and alerts over time to help pinpoint specific events or changes in your system configurations that increased vulnerability internally, or that represent increased external activity against your networks and databases. Slide the shaded Viewer on the bottom graph line to extend the viewable timeframe beyond the last 30 days.
* **Asset Categories, Coverage, and Inventory**: The number of assets currently registered in DbProtect, and the number of assets currently covered by scanning activity are shown at the top of the screen. The categorization of your asset inventory is shown in a donut chart to provide a snapshot of the percentage of your inventory in each asset type (database types). Click a segment of the chart to see asset tags on the right side; the segment pops out of the donut to highlight that portion of the inventory for presentations or discussion.

### Filtering and Generating Reports

When you browse through the data on the dashboards, there are options available to allow you to display the data, export the data as a report, or to create a report job.

#### Filtering

On the Explorer Dashboard, the ability to filter the data is available to quickly search for and access the data that is of the most interest. On any of the report drill-throughs, the filter header will be displayed.

The data displayed can be further filtered by **Asset Type**, **Check Category Type**, **Risk**, **Date Range**, and **Status**. In addition, it can display information from any child organizations that exist under the current organization.

Advanced options are available to further refine the results and allow for multiple conditions to be specified.

After the criteria is specified for filtering, clicking **Apply** will refresh the displayed data. The filters and conditions applied here will apply to the options available under the **Advanced Monitoring** capabilities.

#### Report

When the **Report** option is selected, the ability to export the data in either PDF, HTML, CSV, or XML is available. By applying filter and condition criteria, as explained in [Filtering](#filtering), the data can be focused in on what matters the most. When the **Create Report** button is clicked, a preview of the report will display to confirm the data before it is saved.

#### Job

To create a report job out of the filtering applied, the **Job** button can be selected. Here, the same ability to filter is available; although there are different conditions that can be applied. The conditions under the Job option allow the data to be filtered based on Asset and/or Check criteria.

After selecting the filters and clicking the **Create Job** button, an additional dialog opens. In this dialog, the report format can be selected, and a report filter is displayed. The report filter can be saved as a shortcut to generate a particular report and filter options which can be added to the report in either an Audit Job or a Report Job.

### Alerts

DbProtect Explorer displays alerts differently from DbProtect Core in several ways:

* Adding archived or acknowledged alerts to the list of active alerts is only a button click; you do not have to view archived and current alerts separately and move between tabs to see them.
* You can quickly adjust the risk level to filter the displayed items to High, Medium, or Low, and see alerts from the last 30, 60, or 90 days.
* Multiple filter conditions can be applied to the list at any given time, allowing you to filter down the results as needed to quickly find alerts for specific assets or of particular types. Filters can be set for "contains" or "does not contain" criteria.
* Initial information about a selected alert is displayed in the bottom pane of the page, and more detailed information is available by double-clicking the alert in the list.
* The **Anomalies** tab displays specialized alerts generated by the occurrence of anomalous activity (non-standard usage and access patterns).

### Policies

This view shows what policies are available. These can then be viewed, and custom policies can be created (**Navigation pane** | **Management** | **Policies**) in DbProtect Explorer.

* The **Policies** page defaults to the **Policies Overview** tab, where you can create a new policy or search existing policies and checks.
* Click the **Policy List** tab to display a list of the policies available, create new policies, edit or duplicate an existing policy, and import or export a policy.
* Double-click the policy you want to view, and a new slider will open from the right-side of the screen, displaying the results of the checks performed by the policy.
* View details of any policy, including Risk Level and Knowledgebase information.
* Click **Save As** on a built-in policy to save the policy under another name and make it editable.

### Exploration

Visualization of your DbProtect data (including users, assets, alerts, and vulnerabilities) and how their relationships are managed (rules, checks, and permissions) are available through the Exploration page of DbProtect Explorer.

Expand the nodes of the network to see how DbProtect Explorer aggregates, visualizes, and makes your data accessible to you, allowing you to discover and pursue areas of vulnerability and risk that might not be obvious when looking at charts and graphs alone.

| Selecting | Displays the following |
| - | - |
| Primary Nodes (Assets, Users, Alerts, Vulnerabilities) | A detailed list of the items associated with that node is displayed in a separate Console window. |
| Secondary Nodes | Break out into individual items or categories |
| Tertiary (and lower) Nodes | Breaks out into further categories<br />OR<br />Breaks out to show relationships with other Primary Node items |

#### Exploration page navigation controls

After you have expanded multiple levels of nodes, you may want to zoom in or out, move the network around to look at different areas, close some nodes to focus on a particular area, or change the data being visualized.

Navigation in the Exploration page is easily managed from the controls on the left side of the page.

#### Use the Exploration Scratchpad

As you expand the nodes in your system, you will start to see areas that require attention, and that you might want to look at in more detail or investigate at a later time. Use the **Scratchpad** to capture nodes of interest, with the underlying data, so that you can pursue specific areas of vulnerability or risk with the details you need to close gaps in your system.

Any node with a white halo can be added to the Scratchpad.

**To use the Exploration Scratchpad:**

1. Hold down the shift key while clicking a node with a white halo. The node will appear in the **Scratchpad** slider at the top right of the Exploration window.
2. Hover over the Scratchpad slider to expand it out into the page and view a list of the nodes you have added.
3. Click either the **Exploration Scratchpad** header, or an item in the list, to open the Scratchpad in a new browser tab.
4. Click the arrow next to the node **Type** to expand the individual nodes and view the underlying data.

### Entitlements Exploration

Visualization of your User Rights Review data is available through the **Entitlements Exploration** page of DbProtect Explorer. Using this page, you are able to drill down into various categories (asset type, objects, users, and privileges.)

When you select an asset type it drills down the data for only the selection made, for example, when Microsoft SQL Server is selected.

Upon selection of a bubble in the **Users** category, it will zoom in on what was selected and an information pane with details on the selected information displayed.

Additional information can be seen by selecting one of the items displayed. From this view, additional search parameters can be entered to filter the data further. The ability to export the dataset to CSV is also available.

## Overview of DbProtect workflows

<Note>
  **Note:** The DbProtect workflows refer to the DbProtect Core only, and all referenced instructions are for functionalities that are only available in DbProtect Core.
</Note>

There are two central workflows that most users will follow to protect their organization's database assets:

* Administrative Setup workflow
* Jobs workflow

The individual steps in either workflow may be performed by multiple individuals, according to your organization's roles and responsibilities.

DbProtect Core's automation capabilities are robust, and tasks can be sequenced to run one after another.

Due to this, it is important to note that many tasks will run only after the previous task has completed successfully. For example, a scan job report can only be completed once the scan job has finished.

### Administrative Setup workflow overview

The administrative setup workflow consists of the following steps:

* Create organizations
* Add users and assign roles
* Manage policies
* Register scan engines

#### Create organizations

A DbProtect "organization" contains scannable assets (database servers). Typically, an organization is a group of servers that have similar check requirements based on the server type and/or regulatory environment.

As part of initial setup, the administrator will create organizations to reflect the known and expected structure of databases in the enterprise. You can place an asset in one or more organizations.

For more information, see [Organizations](#organizations).

#### Add users and assign roles

Once users are granted permissions in the organizations, additional tasks such as asset management, job creation, and reporting can be delegated to the users. As part of the Setup Workflow, an administrator will import additional users and grant role access to them:

* Users are accounts that you import from the Windows domain or local machine environment.
* Roles are permission sets that you apply to grant users varying types of permissions within DbProtect. For example, you can allow users permission to:
  * View reports for one or more organizations
  * Manage or run jobs
  * Grant permission to one or more organizations to other users
  * Manage the entire installation

For more information, see [Edit and delete users](#edit-and-delete-users) and [Working with roles](#working-with-roles).

#### View policies

A DbProtect policy is a group of scanning checks. Policies are defined to validate best practices and regulatory, risk, compliance, or database security requirements. DbProtect applies policies to database assets to check configuration, user entitlements, audit and historical activity, and monitor activity in real time. You can customize policies to meet your requirements.

#### Register scan engines

Scan engines are software applications that collect and store data about your network assets. The scan engines must be installed and then registered in DbProtect before DbProtect Core can access the scanners' data.

Scan engines are managed (registered, configured, and unregistered) in the **Setting** section of DbProtect.

See [Register a scan engine](#register-a-scan-engine) for more information.

### Jobs workflow overview

#### Adding assets

An asset is a scannable database instance or scanning component known to DbProtect. Before you can perform other activities such as setting up jobs, you must add the target database instances as assets.

Assets include:

* Databases that you scan
* Database related endpoints, such as SQL redirects
* DbProtect scan engines

You manage assets using the console. You can add database instance entries manually, import entries from a file, and edit existing entries.

For more information about assets, see [Add assets](#add-assets).

#### Set up and run jobs

The **Jobs** page includes four tabs that allow you to see a list of currently available jobs, as well as information about jobs in progress, completed jobs, and jobs scheduled to run in the future.

| Tab | Displays |
| - | - |
| Jobs | Jobs that are available to run, including scheduled and un-scheduled jobs. For more information about adding, editing, and scheduling jobs, see the **Working with Jobs** sections of this guide. |
| In Progress | Jobs that are currently running. The **Progress** and **Status** fields give important information about the health of the job. |
| Completed | Jobs that have been run in the past. Select an item to view details of Job Execution in the lower pane. If a job generates a report, the report is linked from the **Job Execution** details. Click the link to open the report. |
| Scheduled | Jobs that are scheduled to run in the future, including recurring instances and one-time schedules. By default, the list includes jobs scheduled in the next seven days. To list jobs for 30 days, or to select dates, use the control above the list. |

##### Discovery jobs

Discovery is the activity of scanning your network to find database assets. Typically, you perform discovery when you are setting up DbProtect, to quickly populate the assets in your environment. You should also perform discovery periodically to scan for new or unknown (possibly unauthorized) data stores. Discovery can also be used to identify assets previously scanned that are no longer on the network.

Discovery is performed by jobs that you can run on a schedule, or immediately. The results of jobs are available as reports that you can distribute and review.

After initial discovery, you can set up the structure of organizations that allow you to perform further testing. You can also leverage information gathered during discovery to ensure that all discovered assets are accounted for in your organization's asset management inventory. For more information about Discovery jobs, see [Add assets through discovery](#add-assets-through-discovery).

##### Pen test and audit jobs

Pen tests and audits apply policies to validate the security of assets and the data they hold. Pen tests generally investigate the security of data and systems against outside attacks. You can also leverage information gathered during discovery to ensure that all discovered assets are accounted for in your organization's asset management inventory.

Pen tests and audits are performed by jobs that you can run on a schedule or immediately. The job results are available as reports that you can distribute and review. For more information about audit and pen test jobs, see [Set up and run a job](#set-up-and-run-a-job).

##### Rights review jobs

Rights review jobs perform a check of user permissions over assets and the objects they include such as tables and stored procedures. You can use the output of rights review jobs to understand who has access to assets and how they got those permissions. You can use this information in discussion with application owners to help with setting access control policies. For more information about rights review jobs, see [Set up and run a job](#set-up-and-run-a-job).

#### Monitor activity

DbProtect database activity monitoring allows you to set up real-time monitoring and alerting for database activity, based on built-in policies or policies that you customize. You can monitor activity for a specific user, column or table, or any combination.

Monitoring allows you to watch assets for specific behaviors in real time. You can use monitoring to watch for system problems or malicious activity. You can also use monitoring to record the actions of authorized users and monitor privileged user activity as well. You can forward the results of monitoring to other systems, such as a Security Incident and Event Management (SIEM), Governance, Risk and Compliance (GRC), or a Ticketing system.

For more information about Monitoring, see [Set up basic monitoring](#set-up-basic-monitoring).

#### Report on results

DbProtect provides detailed reporting on the results of scans. One or more reports can be run as part of a pen test or audit job. Reports can also be run as standalone jobs or created on demand. Reports, or notifications of report availability, can be delivered by email to users. For more information on reporting, see [Report DbProtect results](#report-dbprotect-results).

#### Investigation and Remediation

DbProtect is designed to help you learn about the strengths and weaknesses of your database assets. It is up to the organization to review the results of testing. The goal of the review will be to identify items that require action, as well as to validate the appropriate access to assets.

This investigation usually requires input from database owners and application developers, as well as the organization's security team.

Based on the investigation of results, the organization will take action to resolve security issues (for example, updating service packs and security policies).

## Getting started with DbProtect workflows

### Administrative Setup workflow

As outlined in [Overview of DbProtect workflows](#overview-of-dbprotect-workflows), the following provides detailed instructions to perform the basic workflow steps of the Administrative Setup.

#### Create an organization

To create an organization:

1. Click **Users & Orgs** on the DbProtect taskbar.
2. On the Organizations tab, click New Organization. The **Create an Organization** dialog opens.
3. Type a **Name** for the organization.
4. Choose the Parent Organization:
   <Note>
     **Note:** If you select an organization from the main list before you click **New Organization**, the parent defaults to the selected organization.
   </Note>
   * Choose **No Parent** to create a top-level organization that has no parent. Top level organizations are created with all available policies selected.
   * Choose **Select a Parent** and click the **Select** button to view the entire organization hierarchy and select the parent for the organization you are creating.
5. **(OPTIONAL)** If you select a parent, select the Copy all parent organization's policies option to inherit all policies currently applied to the parent organization.
   <Note>
     **Note:** This is a one-time action. Future changes to the parent's policies do not affect descendants.
   </Note>
6. Select at least one **Owner** for the organization from the drop-down list. The selected owner will have access to all operational and data view functions for the organization.
   <Note>
     **Note:** Any changes to ownership and other user rights take effect at the next login of a user. This is also true for the administrator making the changes.
   </Note>
7. **(OPTIONAL)** Enter a **Description** to help differentiate this organization from others in the hierarchy.
8. Click **Create** to add the organization.

#### Add users/groups and assign roles

To add one or more users or groups:

1. Click **Users & Orgs** on the DbProtect taskbar.
2. Click the **Users** tab.
3. Click **New User**. The **Create a User** dialog opens.
4. In the **Grant Access To** section, type a **User** or **Group** name and select a domain (if any).
5. **(OPTIONAL)** Enter a **Description**.
6. Click **Add**. The new user is added to the box below the **Description** field.
7. Repeat steps 1 through 6 for any additional users or groups you want to add with identical roles.
8. In the **Add Roles** section, click **Add**. The **Organization Role Selector** dialog opens.
9. Select one or more **Organizations** that the roles will be associated with.
10. Select one or more **Roles** to associate with the selected organizations.
11. Click **Add**. The organization and associated roles are added to the list.
12. Select a **System Role** from the drop-down list. Repeat as needed to add other system roles.
13. Click **Delete** for any organization or system role to remove.

#### View a policy

<Note>
  **Note:** The legacy Policy Editor available in previous releases has been fully deprecated since the v6.6.1 release of DbProtect and is no longer part of the installation package. It has been replaced by the **Policies** page in the DbProtect Explorer. See [Policies](#policies).
</Note>

DbProtect Vulnerability Management allows you to view a policy (for either a pen test or an audit). You can see what security checks are enabled in the policy and detailed information about each check. Details include suggested fix information if it is available. The suggested fix could be a system patch, SQL update query, parameter or configuration change, or a general policy suggestion.

At this step in the workflow, familiarize yourself with the details of some of the built-in policies available in DbProtect. Policies are not applied until you set up a job in the Jobs workflow, but it is helpful to know more about any policy you might want to apply at that time.

To view a policy:

1. On the navigation pane, click **Policies**. The **Policies** page opens.
2. Click the **Policy List** tab.
3. If the policy list is extensive, filter the list using one or all of the following, and click **Apply**:
   * Search the list for policies using the policy name or part of the name.
   * Filter the list by making selections from the **Policy Type**, **Policy Template**, and **Status** options.
4. Select the policy you want to view to see summary information in the bottom pane, or double-click the policy to open the policy details pane.
5. Choose an **Asset** type and expand the **Checks** categories to view individual checks performed in the policy.

#### Register a scan engine

Before registering, you must install the scan engine software. The required network port must be open between the DbProtect console server and the scan engine host.

To register a new Scan Engine:

1. Click **Settings** on the DbProtect taskbar (far right side).
2. Click the **Scan Engines** tab.
3. Click **Register New Scan Engine**.
4. Type an easily recognized **Scan Engine Name**.
5. Enter the **Hostname** or **IP address** and the **TCP Port**.
6. Click **Register**.

When a new scan engine is registered successfully, by default the **Configure Scan Engine** dialog opens.

If you do not need to perform additional configuration you can simply close the dialog.

### Jobs workflow

#### Add assets

There are multiple ways to add assets in the Jobs workflow, including adding manually, importing multiple assets from a CSV file, or running a discovery job to automatically detect and identify assets available on your network.

##### Add an asset manually

To add a single asset manually:

1. Click **Assets** on the DbProtect taskbar.
2. Click **New**. The **Create an Asset** dialog opens.
   <Note>
     **Note:** For additional details about expected values for a field, click the help icon next to the field.
   </Note>
3. Enter a unique, easily recognized **Name** for the asset.
4. Click **Select** next to the **Organization Associations** field to choose an organization from the hierarchy.
   <Tip>
     **Tip:** To associate an asset with more than one organization, after creating the asset, click Org Associations and select the additional organizations.
   </Tip>
5. Select the **Type** of database server you are adding from the drop-down list.
6. Enter the name of the **Database/Instance/SID** for this asset.
7. Enter a **Host** (or IP address) and **Port** to be used for this asset and click **Add Endpoint Below**.
8. Repeat this step to add additional endpoints.
9. **(OPTIONAL)** Click **Add as Preferred** next to one of the endpoints. If no endpoint is set as preferred, the system will use the order of the endpoints as they appear in the list.
10. **(OPTIONAL)** Select a **Version** from the drop-down list and identify the **Platform** for this version.
    <Tip>
      **Tip:** Although the **Version** and **Platform** selections are optional, the values can affect the results of a scan. You should select both if they are known.
    </Tip>
11. **(OPTIONAL)** Click **Add attributes**, enter a **Name** and **Value**, and then click **Set**. Attributes can be used to refine searches. Click **View system attribute names** for a list of attribute names that have special meanings.
    <Note>
      **Note:** If you have integrated DbProtect with CyberArk, you MUST add an attribute (`name="IDENTIFIER_KEY"` and `value="[nameOfCyberArkAsset]"`) to the new DbProtect asset. This asset identifier was set up in CyberArk prior to configuring DbProtect for integration (see DbProtect Install and Upgrade Guide, "Integrate CyberArk and DbProtect").
    </Note>
12. Select the **Create another asset** checkbox if you want to create additional assets after this one is complete.
13. Click **Create**. The asset is added to the list.

<Note>
  **Note:** If an identical asset already exists, the new asset is not added. Assets are uniquely identified by the Host Name, Instance Name, and Port.
</Note>

##### Import assets

Import multiple assets by pasting a list in Comma Separated Value format (CSV). The CSV data must include a header row and a number of fields. Additional fields are optional. See [Appendix E: Asset Import Example CSV Information](#appendix-e-asset-import-example-csv-information) for more information on CSV formats and examples.

To import assets:

1. Click **Assets** on the DbProtect taskbar.
2. Click **Import**. The **Import Assets** dialog opens.
3. In the **Assets** pane, paste the CSV-formatted data. For more information about the data format, click **View Sample File**.
4. **(OPTIONAL)** In the **Asset Identity Descriptors** field, enter the list of fields in the imported data that will be treated as part of the unique asset identifier. By default, the required fields **host name**, **port**, and **instance name** are used.
5. In the **Organization** pane, select the **Organization** where new assets will be created. You can also include organization information in the CSV input.
6. Click **Test Import**. If the test is not successful, make the required changes to the data.
7. When the test is successful, click **Import**.

##### Add assets through discovery

Assets can be added to DbProtect by running a Discovery job.

#### Set up and run a job

To create an audit, pen test, or rights review job:

1. Click **Jobs** in the DbProtect taskbar.
2. Click **New Job** to open the **Create a Job** wizard and see a description of each type of job that you can create. If you know what type of job you want to create, click the down arrow next to **New Job**.
3. On the first page of the wizard, select the **Audit**, **Pen Test**, or **Rights Review** template.
4. Enter a **Job Name**.
5. Click **Select** to open the **Organization Selector**.
6. Select the organization to use for this job.
7. **(OPTIONAL)** Click **Add description** and provide enough detail to differentiate this job from the others you will create.
8. Click **Continue**.
9. On the **Assets** side tab, click **Add Assets** to select the assets that will be tested in this job. See [Add assets to jobs using saved and ad hoc queries](#add-assets-to-jobs-using-saved-and-ad-hoc-queries) for more information.
10. **(Audit and Rights Review jobs only)** Click the **Credentials** side tab. The list of assets you have added is displayed showing the credential status for each asset. Each asset should display a green circle or green check mark for one type of credential, indicating adequate permissions. For any asset that shows **Needs Attention** or **Failed**:
    1. Click **Add Override Credential**. The Add Database Credentials dialog opens.
    2. Select an Authentication type from the drop-down list and provide the necessary information for the type you selected.
    3. Click Test to verify that the authentication type and related credentials are valid.
    <Note>
      **Note:** You can continue to create a job without complete credentials but be aware that jobs without complete credentials may request attention at run time or some steps might fail.
    </Note>
11. Click the **Policy** side tab and select one or more policies to use. For more information about Policies, see [View a policy](#view-a-policy).
12. Click the **Reports** side tab.
13. Click **Add Report**. The **Report** wizard opens.
14. Select a report from This Job's Results (recommended) or click **Other** to view a list of available report templates.
    <Note>
      **Note:** Other reports give access to all available reports, whether or not they provide output related to the job.
    </Note>
15. Click **Next** and complete the **Input Settings** for the type of report you have selected.
16. Click **Next** and complete the **Output Settings** for the type of job you are creating.
17. Click **Save**.
18. Click the **Advanced Settings** side tab and complete the additional settings that are required to perform the job.
19. Click **Create** to save the job.
20. To run the job immediately, select the job on the **Jobs** page and click **Run Now**.
21. To schedule a job for a future time, select it on the **Jobs** page and click **Schedule**, set the **Schedule Type**, **Start Time**, and **Start Date**, and click **Save**.

<Note>
  **Note:** The material and information contained in the User Creation Script is for general information purposes only. Users should not rely upon the material or information included in this script as a basis for correctly creating scan users to successfully perform audit scans against your company's database environment. It is important to review these scripts with your internal Database Administration team and create a process for successfully creating the users needed to execute audit scans.
</Note>

### Set up basic monitoring

To utilize DbProtect's Activity Monitoring capabilities to protect a database, you first need to install and configure a sensor.

#### Register a sensor

Before registering a sensor, you must install the sensor software on the appropriate system. If a sensor is not already installed on your system, see the *DbProtect Sensor Installation and Configuration Guide*.

To register an installed sensor:

1. Click **Monitoring** | **Sensors**. The **Sensor Manager** page opens.
2. Click **Register New Sensor**. The **Registration Manager** page opens.
3. Enter the **IP Address/Host Name** of the sensor machine.
4. Enter the **TCP Port** where the sensor is listening (by default, port 20000).
5. Click **Next**.
6. On the summary screen, click **Finish** to accept the settings, or click **Back** to adjust settings.

DbProtect attempts to contact the sensor. If the sensor can be contacted, registration is successful. If the sensor cannot be contacted, you are notified, and the registration information is not saved.

#### Deploy a policy

After you have successfully installed, registered, and configured the sensor, you must deploy a policy to the sensor to tell it what specific events you wish it to monitor for.

To deploy a policy:

1. Click **Monitoring** | **Policies**. The **Policy Manager** page opens.
2. Click **Deploy** next to a named policy in the list that you want to deploy to the sensor you have prepared. The **Policy Deployment** page opens.
3. Select an available database application from the list of configured sensors and the currently deployed policy for each (if any). You can filter the list in two ways:
   * Type in the **Search** field to look for specific text in the descriptions of the sensor
   * Select the **Only show databases with stale policies** to limit the list to sensors that require updated policies.
4. Select one or more items and use the arrows to move the selected items into or out of the **Deploy policy to** list.
5. Click **Deploy** to deploy the policy to the selected sensor(s). Deployment success or failure will be confirmed on this page.

### Sensitive Data Discovery

The ability to scan database targets for Personally Identifiable Information (PII) and Personal Health Information (PHI) is available. This capability is included under the Vulnerability Management licensing in DbProtect. The databases supported at this time are:

* Microsoft SQL Server
* Oracle
* MySQL
* PostgreSQL

To run this check, create a new policy that includes the "Sensitive Data" checks, or use the built-in *Sensitive Data Discovery* policy.

#### Terms & Scoring

Current industry standard terminology and regulations in the United States are used as a basis for identification of the data. The scoring of the data is based on information discovered from the database schema and a sampling of the first ten (10) rows of data contained in the database tables. No information is ever removed from the database, as all analysis and pattern matching is done local to the target database. For more information on the scoring, see [Appendix C: Sensitive Data Discovery (SDD)](#appendix-c-sensitive-data-discovery-sdd).

The following terms are considered both PII and PHI:

* First Name, Middle Name, Last Name
* Address, PO Box, City, County, State, Country, Zip Code
* Gender, Birth Date
* Telephone Number, Fax Number, Email Address, IP Address
* Social Security Number, Social Insurance Number, Health Card Number
* Fingerprint, Voiceprint, Full Face Photo

The following terms are considered additionally for PII:

* Driver's License, Passport Number

The following terms are considered additionally for PHI:

* Age, Date of Death, Admission Date, Discharge Date
* Race, Ethnicity, Religion
* BMI, Web URL, Medical Record Number
* Health Insurance Provider, Health Insurance Group ID, Health Insurance Member ID
* Certificate/License Number, Vehicle Number, Device Identifier

#### Sensitive Data Discovery reporting

The results are all rated "Informational" and are classified as "Facts" in the results. To view the resultant data from the Sensitive Data Discovery checks, the "Check Results Details" report will need to be run.

## Working with Organizations, Users, and Roles

Organizations are flexible containers for database assets where you can:

* Manage assets
* Enforce role-based access control for users
* Access, separate and/or filter data
* Manage the availability of policies for vulnerability management
* Impose operational restrictions for scan engines

You need to define at least one organization to use core product functions.

For DbProtect environments where there are no security or privacy concerns, there is no need to build any further organizations. Assets may be added through Asset Management or as results of a discovery.

If you require finer access controls, you may need to create more organizations.

You may create one or more hierarchical trees of organizations. At the time of creation, you may select one or more Owners. An Owner is a role by which a user can be given full control over the organization. If you do nothing, you will be added as the owner of all organizations that you create. Once an organization is created, any affected users will have to log out and log back in to the product to use their new privileges.

Once you start creating organization structures, you might find the advanced functions to copy organization structure / contents helpful. See [Copy an organization's features](#copy-an-organizations-features) for more information.

When creating organizational hierarchies, each root organization is granted access to all available vulnerability management policies. As an Administrator, you may choose to restrict policies in any organization. See [Apply policies to an organization](#apply-policies-to-an-organization) for more information.

A child organization can only be given policies that are granted for use in its parent. When you select a subset of policies to be available in an organization, there are two areas in which this is reflected:

* displaying a restricted list while setting up pen test or audit jobs
* filtering all reporting and dashboard data through a filter of only the elements enabled in the policy

### Organizations

#### Edit an organization

To edit an organization:

1. Open the **Users & Orgs** page | **Organizations** tab.
2. Select an organization and click **Edit**. The **Edit Organization** dialog opens.
3. Modify the **Name**, add and delete **Owners**, and add or modify the **Description** of the organization.
4. Click **Save** to apply the changes to the organization.

#### Copy an organization's features

You can copy assets or descendants (child) structures from one organization to another.

To copy assets to another organization:

1. On the **Organizations** tab, select the source organization that contains the assets you want to copy.
2. Click **Copy** | **Copy Assets to**. The **Copy Assets to** dialog opens.
3. Select the target organization and click **Copy**.

To copy descendant (child) structure:

1. Select the source organization that contains descendants (children) you want to copy.
2. Click **Copy** | **Copy Child Structure to**. The **Copy Child Structure to** dialog opens.
3. Select the target organization and then click **Copy**.

#### Delete an Organization

<Warning>
  **Caution:** Deleting an organization also deletes child organizations.

  Deleting an organization deletes all associated jobs and history from DbProtect. Deleting an organization can result in discovered assets being completely deleted from DbProtect (if the assets are not associated with any other organization).

  Before deleting an organization, carefully review the warning presented and ensure you know what assets will be affected.
</Warning>

* To delete an organization, select it and then click **Delete**.

#### Apply policies to an organization

Policies are collections of checks that are used to run jobs.

To apply policies to an organization:

1. Click **Users & Orgs** | **Organizations** tab.
2. Select the organization and then click **Manage Policies**. The **Manage Policies** dialog opens.
3. Select a policy (click and hold `Ctrl` to multi-select) and use the arrows to add or remove them from the **Selected Policies** list.
4. Click **Save** to save changes.

<Note>
  **Note:** You should remove unused policies from child organizations.
</Note>

### Edit and delete users

To edit a user or group:

1. Click **Users & Orgs** | **Users** tab.
2. Select the user or group you want to modify and click **Edit**. The **Edit User** dialog opens.
3. Add or modify the **Description** as desired.
4. In the list of **Organization Roles**, click **Delete** next to any organization-role combination that is no longer valid for the user.
5. Click **Add** to add new organization-role combinations to the user.
6. In the **System Roles** list, click **Delete** next to any system role that is no longer valid for the user.
7. Select new **System Roles** for the user from the drop-down list.
8. Click **Save** to update the user's roles.

To delete a user or group:

1. Select the user or group.
2. Click **Delete**.

### Working with roles

#### Organization roles

These roles affect access only within the specific organization to which they are applied. A user that is associated with more than one organization can have different roles within each organization. Use of product functions for assets in each organization is limited by the user's roles in that organization.

**DbProtect Organization Roles**

| Org Role | Permissions | Primary Functions |
| - | - | - |
| Owner | Grants access to all operational and data view functions within an organization | All non-administrative functions |
| Job Manager | Grants access to all job operations functions within an organization | Creation and management of jobs, including scheduling, handling error conditions, setting up operational notifications for stakeholders, performing all data collection functions |
| Credential Manager | Grants access to all credential management functions within an organization | Creation and management of credentials, including export and import |
| Data Viewer | Grants access to all dashboard and reporting functions within an organization | Consume dashboard and report content, view generated reporting content from jobs, provide appropriate data artifacts to management and operational stakeholders |
| Asset Manager | Grants access to all asset management functions within an organization | Creation and management of assets including asset import |
| Auditor | Grants view-only access to all functions within an organization | Internal or external auditor needing to verify proper operational use and report production |
| Check Results Viewer | Grants view-only access to Scan (Check) results for an Organization | Consume dashboard and report content for Scans (Checks) |
| Rights Review Results Viewer | Grants view-only access to Rights Review results for an Organization | Consume dashboard and report content for Rights Review |

#### System roles

These roles apply to the setup, configuration, and maintenance of the system. They do not affect access to operations or reporting.

**System Roles**

| System Role | Permissions | Primary Functions |
| - | - | - |
| Administrator | Grants access to all administrative functions | User definition, organization definition, management of licenses and scanners |
| Administrative Data Viewer | Grants access to view specific types of report results | Consume dashboard and report content for Scans (checks), Rights Review for all organizations |
| Auditor | Grants view-only access to all administrative functions | Internal or external auditor needing to verify proper organization, user and role definition |
| Org Owner | Used in conjunction with an Owner role for a particular organization. Allows an organization owner to create descendant organizations | Delegation of setup and maintenance of the DbProtect organizational structure for lines of business or multi-tenancy |

## Working with policies in DbProtect Explorer

### Create a new policy

DbProtect Vulnerability Management allows you to create an audit policy by defining the security checks it contains. This is known as a user-defined policy.

<Note>
  **Note:** The legacy Policy Editor included in previous version of DbProtect has been fully deprecated and is no longer available. The new policy editor is in DbProtect Explorer and can be accessed only if the installation/upgrade of DbProtect included DbProtect Explorer.
</Note>

To create a new policy:

1. In DbProtect Explorer, click **Management** | **Policies** in the left navigation menu.
2. Click **New Policy** at the top of the page. The **New Policy** dialog opens.
3. Provide a **Policy Name** and **Description** (both are required fields).
4. Click **Create**. The **User-Defined Audit Policy** pane opens.
5. Select the correct **Asset** type from the drop-down list on the left.
6. Explore the available **Checks** to determine which ones you would like to add to the new policy:
   * Click the arrow beside each check category to expand it.
   * Click a check name in the list to view a description of the check in the right-side pane.
   * Select each individual check you want to include or select the top-level category name to select all checks within the category.
7. Click **Save Changes** when you have selected all the checks you want to include in the policy.
8. Click the **X** button at the top-left to close the page.

### Rename or edit a policy

DbProtect Vulnerability Management allows you to edit a policy. You cannot permanently modify built-in policies. However, you can edit a built-in policy and use the "save as" function to save the edited policy under a different name.

To rename or edit an existing policy:

1. Click **Policies | Policy List**.
2. Modify the **Search** criteria in the left pane to filter the list, or move through the list using the navigation controls at the bottom right of the page.
3. Select the policy you want to modify and click **Edit**. The **User-Defined Audit Policy** pane opens.
4. Click the **Edit** (pencil) icon to modify the policy name (if required).
5. Modify the **Asset** and **Checks** selection for the policy as needed.
6. Click **Save Changes** (or **Save As** to create a new policy with the modified settings).

### Search policies

DbProtect Vulnerability Management allows you to search policies for checks that match specified text search criteria. For instance, you can search for a specific CVE reference number.

To search policies:

1. Select the organization the policy was assigned to from the **OrgSelector** drop-down list at the top right of the pane.
2. Select the appropriate filter criteria for **Policy Type**, **Policy Template**, and **Status** for the policy you are searching for.
3. Enter the policy name (or part of the name) into the **search here** field to look for a specific policy.
4. To save a search, type a **Search query name** and click **Save & Apply**.
5. To run an existing search, click **Saved Searches** and select the search you want to run.

### Set up policy check report filters

DbProtect allows you to include report filters with specific checks in user-created pen test and audit policies. A report filter can be used to exclude specified parameter value(s) from being reported as a violation if found during a pen test or audit. You can add report filters only to user-defined policies.

<Note>
  **Note:** Report filters are added via checks; therefore, a check must be enabled before you can access the **Report Filters** tab.
</Note>

#### Report filter examples

Report filters are generally used when running access control checks, since many of these checks provide a list of all possible access points, including access points that are acceptable or required for an application to function.

The following are some examples of report filters:

* **Oracle Check:** Role granted WITH ADMIN option<br />**Report filter:** Role=DBA<br />This will result in DbProtect not reporting violations found for the DBA role for this check.
* **Oracle Check:** Easily-guessed database password<br />**Report filter:** Username=John<br />This will result in DbProtect not reporting violations found for username: John for this check.
* **Oracle Check:** Easily-guessed database password<br />**Report filter:** Username=John<br />**Report filter:** Password=12345<br />This will result in DbProtect not reporting violations found for username: John or any username with the password of '12345'.

#### Add report filters to a policy

To add a report filter:

1. In the **Policy List** tab, select the user-defined policy to which you want to add report filters and click **Edit** at the top of the list. The policy details slider opens.
   <Note>
     **Note:** If you double-click on the policy to open it, you will not be in **Edit** mode and will not be able to select a check until you click **Edit** in the top-right corner of the slider.
   </Note>
2. Select a check on which you want to filter (checkbox next to the check name must be selected). Once selected, the **Report Filters** tab is displayed next to the **Knowledgebase** tab.
3. Click the **Report Filters** tab, then on **New Filter**. The **New Report Filter** slider opens.
4. Select **Global** or **Asset** from the **Scope** drop-down list:
   * **Global:** Report filters will be applied to all assets included in a report generated based on this user-defined policy, if no individual database assets are defined.
   * **Asset:** If specific assets are defined, the report filter will be applied only to the database assets defined in the filter.
5. Expand the **Condition** drop-down list and select one of the parameters available for the check you selected.
6. Provide the **Value** for the parameter, then click the add icon to add the condition to the filter.
7. Repeat steps 5-6 to add as many conditions as required.
8. If you have selected to define specific assets, select an asset from the **Asset Type** drop-down list.
9. Select **Ipv4** and provide the **IP** address for the asset.
10. Set the **Port** number and provide a descriptive **Name** for the asset.
11. Click the add icon next to the **Asset Type** you select. The asset is added to the filter.
12. Repeat steps 8-11 for each asset you want define for this filter.
13. If an asset is incorrectly defined, you can modify the details, or click the remove icon to remove it from the filter.
14. Click **Save Changes** in the top-right corner of the slider before closing the report filter.

#### View report filters

To view a report filter:

1. Click the enabled check containing the report filter you want to view.
2. Click **Report Filters**. The **Report Filters** dialog opens, displaying a list of report filters.
3. Click the **+** icon to expand the details of each report filter. Any report filter with a **+** contains risk acceptance information that can be viewed.
4. Click **OK** to close the **Report Filters** dialog.

#### Edit report filters

To edit a report filter:

1. Click the enabled check containing the report filter you want to edit.
2. Click **Report Filters**. The **Report Filters** dialog opens, displaying a list of report filters.
3. Click on the report filter you want to edit.
4. Click **Edit**. A dialog opens, displaying editing options for the report filter.
5. Make your desired edits and click **OK**.
6. Click **OK**. Your edits are automatically saved.

#### Delete report filters

To delete a report filter:

1. Click the enabled check containing the report filter you want to delete.
2. Click **Report Filters**.
3. Select the report filter you want to delete.
4. Click **Delete**.
5. Click **Yes** to verify the deletion. This will delete the report filter and any risk acceptance information you included for the selected report filter.
6. Click **OK** to close the **Report Filters** dialog.

### Import a policy

To import a policy:

1. In the **Policy List** tab, click **Import**. The **Import Policies** slider opens.
2. In the **Source** drop-down list, select either **Load file** or **Copy & Paste**:
   * If you select **Load file**, click the **Load** button to navigate to and select the file to import.
   * If you select **Copy & Paste**, copy valid XML into the editing box. If the XML is invalid, it is indicated above the box. Edit the XML as needed to eliminate the **Invalid XML** warning.
   <Note>
     **Note:** Click the copy icon to copy the contents of the XML editing box to another location or application.
   </Note>
3. Click **Submit** to begin the policy import.

### Export a policy

DbProtect allows you to export user-defined policies. This is useful if you want to transfer policies between DbProtect Core and Explorer. Exported policies include any user-defined checks that are part of the policy.

<Note>
  **Note:** You can only export user-defined policies. You cannot export built-in polices.
</Note>

To export a policy:

1. In the **Policy List** tab, click **Export**. The **Export Policies** slider opens.
2. Select the checkbox next to each policy you want to export, or select the top checkbox to select all policies in the list.
3. Click the **Data to Export** arrow and choose between exporting all data, or just the exceptions.
4. Click **Submit** to begin the export.

### Activate/deactivate a policy

All policies can be activated or deactivated as required. Deactivated policies are not removed or deleted but are not run until reactivated.

To activate/deactivate a policy:

1. On the **Policy List** tab, select the policy you want to activate/deactivate.
2. Click the appropriate button at the top of the list to change the status of the policy.
3. Click **OK** to save changes.

## Working with scan engines

All activities involving scan engines are performed from the **Scan Engines** tab of the **DbProtect Settings** (far right of DbProtect taskbar).

For users with adequate privileges to run jobs that scan databases, you need to define at least one scan engine. First, you need to download and install the scan engine on a host of your choice. Scan engines may be installed on the same host as the DbProtect application server, but also may be installed on other hosts. For proper functioning of scans, you may need to install database drivers on the same host as the scan engine(s).

To establish a trust between your DbProtect system and its scan engines, you need to register each scan engine. See [Register a scan engine](#register-a-scan-engine) for more information.

For DbProtect environments where there is only one scan engine and no security concerns about users accessing scan engines, there is no need for further configuration. If your scan engine is shown to be Alive, it is ready for use.

When you have installed a new SHATTER Knowledgebase, you will need to push this out to each scan engine. See [Update the SHATTER Knowledgebase](#update-the-shatter-knowledgebase) for more information.

### Advanced scan engine configuration

After registering a scan engine, you have the option to configure some advanced options that impact its use. Setting these configuration options are not required. You may return to set or change these options later.

The definitions of these configuration options are described below.

| Option | Details |
| - | - |
| Discovery Network Interface | Directs requests for discovery to be sent out of a particular physical networking interface on the scan engine host. If this is unset, jobs that discover databases will loop through each live network interface. If this is not the preferred behavior, select a particular network interface to be used for discovery. |
| Availability | Declares a particular scan engine offline. This is usually motivated by the need for maintenance / upgrade on the scan engine or its host. It may also be used when the administrator does not wish to have scan jobs fulfilled by the selected scan engine. Any new scan requests will not run against offline scan engines. |
| Organization Restrictions | Allows only certain organizations to have access to particular scan engines. When nothing is defined, the system determines the best-fit scan engine based on availability and load. When restricted, only the allowed organizations can run jobs on the scan engine. This is typically used for scanning sensitive network segments where restricted access is necessary. It may also be used when special database drivers are needed to connect to certain databases and cannot coexist with other drivers. |
| Group | Associates an asset directly with a scan engine. When nothing is defined, the system determines the best-fit scan engine based on availability and load. When a Group Name is defined, only assets that have a custom asset attribute called scanGroup, whose value matches the value entered for Group Name, will be able to use this scan engine. Likewise, an asset that has the scanGroup custom asset attribute will only be scanned using a scan engine with a matching Group Name. This definition is most commonly used to model specific access points to networks or define datacenter proximity to scan engines. |

### Additional per Scan Engine configuration

**Target x509 Certificate Validation**: ScanEngine v3.25 and later can be configured to validate x509 certificates provided by the scan target. This is a setting in the ScanEngine configuration file and applies to all hosts scanned using this ScanEngine. To enable this, add the following two values to `appsettings.json` in the ScanEngineHost installation folder (typically at `%ProgramFiles%\LevelBlue\ScanEngineHost\appsettings.json`)

```json appsettings.json theme={null}
"EnforceStrictVerification":true,
"EnforceTlsVerification":true,
```

### Unregister a Scan Engine

To unregister a scan engine:

1. Click **Settings | Scan Engines**.
2. Select the scan engine from the list and click **Unregister**.

<Note>
  **Note:** Unregistering does not uninstall the scan engine software. In most cases, you should unregister first and then run the uninstallation from the **Start** menu on the scan engine host.
</Note>

### Configure a scan engine

To configure a scan engine:

1. Select a scan engine in the list and click **Configure**. The **Configure Scan Engine** dialog opens.
2. On each of the side tabs of the dialog, you can perform the following tasks:
   * **Discovery Network Interface**: Set the network interface to be used by the scan engine (if more than one is available on the server). This option directs the scanning to a specific subnet.
   * **Availability**: Set the scan engine as **Available** or **Unavailable** (for instance, if the server is overloaded or you do not want to scan specific subnets).
   * **Organization Restrictions**: Set the organizations that can use this scan engine.
   * **Group**: Set an asset group so that the scan engine scans only the assets in the group. The restriction is evaluated at runtime along with any other restrictions made in the scanning job.
3. Click **Save**.

### Update the SHATTER Knowledgebase

The SHATTER Knowledgebase content is a collection of regularly updated framework of controls and checks that can be added to DbProtect to provide the most current protection to your databases, leveraging industry standards like CIS and DISA STIG and others.

LevelBlue typically provides an updated version of the SHATTER Knowledgebase every four to six weeks. You can update the SHATTER Knowledgebase on the DbProtect console server by downloading the latest package from LevelBlue and installing it.

To update the SHATTER Knowledgebase:

1. When a new Knowledgebase is available, click **Settings** | **Scan Engines**.
2. Select the scan engine in the list and then click **Update Knowledgebase**. When the update is completed, **Update Successful** will be displayed above the scan engine list.

<Note>
  **Note:** When a new scan engine is registered, the latest SHATTER Knowledgebase is always used.
</Note>

## Working with assets

### Edit or delete an asset

To edit the basic properties of an asset, such as the name, instance, endpoints, and attributes, select the asset and click **Edit**.

<Warning>
  **Caution:** Deleting an asset will also result in the deletion of all historical scanning associated with that asset.
</Warning>

To delete an asset, select the checkbox next to the item and click **Delete**.

### View asset details and credentials

To view details of an existing asset:

* Select the asset from the assets list. The **Details** and **Credentials** tabs are displayed in the lower pane of the window. If these tabs are not visible, click **Expand** at the bottom right of the page.

To view basic information about testing and monitoring activity for this asset:

1. Click **View Summary Report**. The **Summary Report** opens in a separate browser window.
2. Generate one of the drill-down reports (displayed as links below each report segment) for more detailed information.

To view credentials that are configured for the asset:

* Click the **Credentials** tab. The details of the asset's credentials (whether shared or individual) are displayed.

### Add/modify/remove attributes for multiple assets

To add, modify, or remove attributes for one or more assets:

1. Select the checkboxes next to the assets with attributes you want to modify.
2. Click **Attributes**. The **Manage Attributes** dialog opens.
3. To add an attribute:
   * Enter a new Attribute Name and Value for all the assets you have selected. System-reserved attribute names are shown on the **Pre-Defined Attributes** table.
4. To modify an existing attribute:
   * Existing attributes and values for the selected assets are listed. If an attribute has different values for different assets, click the arrow to the left of the attribute name to view all values.
   * Select an attribute to populate the **Name** and **Value** fields, edit the fields as needed, and then click **Set**.
5. To remove an attribute:
   * Click **Delete** next to an existing attribute to delete it.
   <Warning>
     **Caution:** Deleting an attribute will delete it for all assets you have selected.
   </Warning>
6. When you have set all attributes, click **Save** to apply the changes.

### Add/modify/remove organization associations

To add or remove organization associations for one or more assets:

1. Click **Assets** on the DbProtect taskbar.
2. Select the checkboxes next to the assets you want to associate an organization with.
3. Click **Org Associations**. The **Organization Selector** opens.
4. Select the checkbox next to each organization you want to associate the asset(s) with.
5. Click **OK**.

### Manage credentials

DbProtect can use three types of credentials to run scans that require them. Since credentials can be defined at various levels of scope, jobs will evaluate and use credentials in the order of precedence as follows:

* **Job-based credentials**: defined as part of a job (see [Set up and run a job](#set-up-and-run-a-job))
* **Asset-based credentials**: defined for a particular asset
* **Shared credentials**: defined for a group of assets matching a search expression

<Note>
  **Notes**

  * If more than one credential is defined for an asset, the job will evaluate the credentials in the above order. Credentials can only be used in the same organization in which they are defined.
  * If credentials for an asset are not correct at job runtime, you can update the credentials and continue the job (depending on job settings).
</Note>

#### Add credentials to an individual asset

To add credentials to an individual asset:

1. Click **New Credentials** and then select the type, either **Database** or **Windows**. The **Add Credentials** dialog opens.
2. Select an existing **Credential Group** or click **New** to create a new group:
   1. Type a name for the group.
   2. Select the organization to add to the new group.
3. Select the Authentication Type.
4. Enter the credential information appropriate for the type, and then click **Test**.
   <Tip>
     **Tip:** For additional details about expected values for some fields, click the help icon next to the field.
   </Tip>
5. If the test is successful, click **Save** to save the credentials for this asset.

<Tip>
  **Tip:** To test one or more sets of credentials, select them using the checkboxes, and then click **Test**.
</Tip>

#### Delete asset-based credentials

* To delete the credentials for an asset, select the checkbox next to the item and click **Delete**.

<Note>
  **Note:** Asset group and shared credentials cannot be deleted from this pane.
</Note>

#### Import and export credentials

To import credentials in CSV format:

1. In the upper right of the **Assets** page, click **Manage Credentials | Import Organization Credentials**.
2. Paste the data from a CSV file into the **Credentials** field. For a sample of the data format, click **View** sample file.
3. Select an **Organization** from the hierarchy.

   <Warning>
     **Caution:** If you have integrated CyberArk with DbProtect, you MUST add the following line to the credentials:

     `vault id = [vault id for the DbProtect vault created during setup]`
   </Warning>
4. Click Test Import.
   * If the test is not successful, edit the CSV data.
   * If the test is successful, click **Import**.

To export credentials in CSV format:

1. In the upper right of the **Assets** page, click **Manage Credentials | Export Organization Credentials**.
2. Select an **Organization** from the hierarchy and click **Export Credentials in CSV Format Below**.
3. Copy the resulting CSV data from the **Credentials** field.

<Note>
  **Note:** Passwords are included in encrypted format.
</Note>

#### Create/modify/delete per-asset credential groups

Management of per-asset credentials is performed by selecting the asset and then using the **Credentials** tab in the lower pane.

To create/modify/delete per-asset credential groups:

1. In the upper right of the **Assets** page, click **Manage Credentials | Manage Per Asset Credential Groups**.
2. Click **New Group** to add a group to an organization, type a **Credential Group Name**, select the organization it should be added to, and click **Create**.
3. Select the checkbox next to an existing credential group name, click **Edit** to modify the name of the group, and click **Update**. The modified group name is displayed.
   <Note>
     **Note:** You cannot change the organization associated with an existing credential group. To do this, you must delete the existing credential and create a new one with the correct organization selected.
   </Note>
4. Select the checkbox next to any credential group you want to remove and click **Delete**.

#### Create/modify/delete shared credential groups

DbProtect allows you to create shared credential groups that contain credentials common to a set of assets. Whenever a job requires credentials for an asset and no per-job or per-asset credential is successfully applied, the job will attempt to use shared credentials.

<Warning>
  **Caution:** Use of shared credentials is possible and often favored for large scale deployments where it is advantageous to set up a single DbProtect-specific shared user account and credentials across similar assets for scanning jobs. However, this can be exploited and is not a security best practice. Leverage DbProtect Activity Monitoring to create a job to monitor for abuse of such accounts!
</Warning>

To create/modify/delete shared credential groups:

1. Click **Manage Credentials | Manage Shared Groups**.
2. To add a new credential group, click **New Group**. The **Create a Shared Credential Group** dialog opens:
   * Type a Credential Group Name.
   * Click in the Organization field, select an organization from the hierarchy, and click OK.
   * Define the group using an asset search query (see [Search assets](#search-assets)).
   * Click Create to create the group.
3. Edit a credential group's membership:
   1. Select a group and click **Edit**.
   2. Modify the name and/or the asset query, and then click Save. You cannot change the organization associated with the group.
4. Add credentials to a group:
   1. Select a group, click **Add Credentials** and select the credential type from the list. The **Add Credentials** dialog opens.
   2. Select the **Authentication Type** from the drop-down list and provide the information required to complete the authentication.
   3. Click **Save**.
   <Note>
     **Note:** For additional details about expected values for some fields, click the help icon next to the field.
   </Note>

* To delete a credential group select it in the list and then click **Delete**.
* To close the shared groups window, click **OK**.

<Note>
  **Note:** The shared credential dialog does not provide a test option. Before running jobs that use shared credentials you should test the credentials for some or all of the assets by selecting the asset from asset search results and using the credential tab on the lower pane.
</Note>

### Search assets

You can limit the list of assets presented on the Assets page by performing a search. Search queries can be defined using either or both of the following options:

* Apply one or more "facets". Facets are specific attributes of assets that have a limited number of possible values, such as database type and network location.
* Apply a search expression, optionally using Boolean, likeness, string, and arithmetic operators.

<Note>
  **Note:** If you define both an expression and facets, only items matching both will display in the results.
</Note>

Search queries can be saved for later use. Search queries can also be constructed and saved in the **Search** pane, on the left side of the **Assets** page. If this pane is not visible, click the **Expand Pane** icon at the top left of the **Asset Search Results** pane.

#### Filter with facets

You can limit the search by one or more of the following facets:

* **Databases:** Database technologies and versions, such as Microsoft SQL Server 2012 Express
* **Networks:** IPv4 class A or class B networks such as `10.*.*.*` or `10.2.*.*`
* **Platforms:** Operating system versions such as SCO Unix or Microsoft Windows x86
* **Organizations:** Groupings of assets that you have created

#### Set up a search query

To set up a search query:

1. Select the checkbox next to each facet item you want to include in the search:
   * Click the arrows to expand each facet type
   * Click **more** to view a full list of items for each facet type
   * Click **all** next to a facet type to select all items
   * Click **clear** to remove all selections for a facet type
2. Click **Update Search Results** to apply the facet and search expression selections to the list on the Asset Search Results page.
3. Click **Reset** at the bottom of the pane to reset all facet and search expression selections.
4. Click **Save Search Query As** at the bottom of the pane to save the facet and search expression selections for later use.

#### Use search expressions

Use a plain text search to look for the text in any text field of an asset. For example, if you enter `express` in the **Search** field and click **Update Search Results**, the results include assets with a name or a database instance name that contains the string express.

Expressions must be enclosed in parentheses ( ) and can include operators and asset attributes.

<Note>
  **Notes:**

  * An expression using a like operator that does not include explicit **%** characters (any substring) assumes that they are present at the beginning and at the end of the pattern. For example, `~ 'test'` is treated as `~'%test%'`.
  * The operators **exists** and **not exists** can be used only with attribute names.
  * Single or double quotes can be used when writing strings (the opening and closing quote must be the same). For example, `'test'` is the same as `"test"`.
</Note>

The tables below show valid operators and some available attributes.

**Search Query Operators**

| Operator | Meaning and Example |
| - | - |
| `=` `!=` | Equals, does not equal<br />`(type != 'oracle')` matches items that are not type *Oracle* |
| `~` `!~` | Like, not like<br />`(type ~ 'sql')` matches items where the type contains the string *sql* |
| `>` `>=` `<` `<=` | Greater than, Greater or Equal, Less than, Less or Equal<br />Performs string comparison<br />`(host > '10.1')` matches items with network (host) string of *10.2.\*.\** and above, or alphabetic host names |
| `exists` | Attribute is defined for the item<br />`(not exists scanGroup)` matches items that do not have a scanGroup attribute |
| `in` | Value is one of the listed values<br />`scanGroup in ('west', 'north')` matches items that have a *scanGroup* attribute with one of the two listed values |
| `and` `&&` | Logical AND<br />`(type='Microsoft SQL Server' && administrator = 'mike')` |
| `or` `\|\|` | Logical OR<br />`(type = 'Microsoft SQL Server' or name like 'IBM')` |
| `not` `!` | Logical NOT<br />`(osType = 'windows' and type != "Microsoft SQL Server")` |
| `%` | Wildcard (zero or more characters)<br />`(name ~ 'houston%')` matches items with names beginning *houston* |
| `_` | Wildcard (exactly one character)<br />`(name ~ 'route_6')` matches (for example) *route66* |

**Pre-Defined Attributes**

| Attribute Name | Function |
| - | - |
| Type | Database Server Type |
| osType | Operating System |
| Name | Asset Name |
| Host | Networks |

To use a search expression with facets:

1. Type the search expression in the **Search** field.
2. Select the facets you want to include in your search.
3. Click **Update Search Results**.
4. Click **Reset** at the bottom of the pane to reset all facet and search expression selections.
5. Click **Save Search Query As** at the bottom of the pane to save the facet and search expression selections for later use.

#### Use saved search queries

Search queries can be saved to quickly return to a custom view of the asset search results. You can also use saved queries when you create jobs.

To save a search query:

1. Set up the query (facet and search expression selections) as desired.
2. Click **Save Search Query As** at the bottom of the pane.
3. Type a **Name** and select an **Organization** to associate the query with.
4. Click **Save**.

To use a saved query:

1. Click **Saved Search Queries** at the top of the Search pane and select an item from the list. The Asset Search Results pane will be updated to match the query.
2. Modify the query as desired and click **Save** above the search expression field.
3. Click **Close** above the search expression field to return to an unfiltered view in the Asset Search Results pane.

### Asset groups

There are cases when it makes sense to encapsulate several assets into one asset group and to operate on this group as one unit. Some examples of when this can be useful are:

* **Oracle 12c in multi-tenancy mode**: You can create individual assets corresponding to individual Pluggable Databases (PDBs), and the Container Database (CDB), and then mark them as a part of one group representing the entire database instance.
* **Oracle RAC**: You can create individual assets corresponding to various databases that participate in the high-availability configurations of one RAC and mark them as a part of one group.
* **Windows Server Failover Clusters**: You can create individual assets corresponding to individual instances that work together to provide the AlwaysOn and High-availability features and then mark them as a part of one group.

The same goes for any assets it makes sense to group into a logical unit of work.

Once several assets are marked as being part of an asset group, you can easily run jobs against these assets and report on them together. If the composition of the asset group changes in the future, the jobs will correctly run against the latest assets that are included in the group.

#### View the assigned asset group for an asset

If you are uncertain which asset group (if any) an asset has been assigned to:

1. Click **Assets** on the DbProtect taskbar.
2. In the **Asset Search Results** pane, mouse-over any column header and click the down arrow that appears on the right side.
3. Choose **Columns** | **Asset Group**. The **Asset Group** column will be visible, and if the assets have been assigned to an asset group, the group name will be displayed in the column.

#### Set up asset group credentials

If the assets in a group share the same credentials, you can set up a shared credential group using the asset group.

To set up shared credentials using an asset group:

1. **Add attributes to multiple assets** (previously known as Bulk Attribute Management), using "assetGroup" as the **Attribute Name** and the name you want for the asset group as the **Value**.
2. **Add a shared credential group** and use the string `assetGroup="[assetGroup Name]"` for the asset search query.

#### Use an asset group in a job

It can be useful to run a job against an asset group rather than running separate jobs against individual assets.

To run a job against an asset group:

1. Add attributes to multiple assets, using "assetGroup" as the **Attribute Name** and the name you want for the asset group as the **Value**.
2. Click **Jobs** page | **Jobs** tab.
3. Click **New Job** and select the type of job you want to create.
4. Enter a **Job Name** and select the **Organization** the job will be run in.
5. Click **Continue**. The **Edit Job** dialog opens to the **Assets** side tab.
6. Click the **Ad Hoc Query** option at the top of the Assets list.
7. Type or paste the following string into the **Asset Query Search** field:

   `assetGroup="[assetGroup Name]"` where `[assetGroup Name]` is the name you gave to the asset group when setting up the attributes.
8. Click **Search**. The assets you provided asset group attributes for are listed in the **Asset Preview** pane.
9. Click **Create**. Continue with the job set up.

## Working with Jobs

DbProtect offers support for various types of security testing jobs

| Job Type | Description |
| - | - |
| Audit | An audit tests the security of your application using an "inside out" approach. Audits require that you have authenticated access to the target database systems. An audit checks the selected assets for weak passwords, misconfigurations, default accounts, missing patches, and other settings that could leave an asset vulnerable to attack or compromise. See [Set up and run a job](#set-up-and-run-a-job) for instructions on setting up an audit job. |
| Pen Test | A pen test assesses the security of your applications by running security checks, based on a policy you choose.<br /><br />Pen tests:<br />• are run from an "outside-in" perspective<br />• give a good analysis of what a hacker or intruder might discover when attempting to bypass your application's defenses<br />• commonly uncover misconfiguration errors in addition to well-known application vulnerabilities.<br /><br />A pen test probes your database from an external or "outside-in" perspective. The test queries network services anonymously to look for a variety of information. When you set up a pen test you do not provide a username or password.<br /><br />During a pen test, DbProtect can run tests which could result in acquiring a valid username and password that any anonymous attacker could discover and potentially use to authenticate to the application. In such cases, DbProtect performs the authentication to gather additional information from the application. The test may connect to the database and gather username and password hashes, or configuration values. A pen test does not make any updates or changes to your database. See [Set up and run a job](#set-up-and-run-a-job) for instructions on setting up a pen test job. |
| Rights Review | Rights review is a deep analysis of user and role entitlements on a database. This type of scan analyzes database user and role privileges, to help guard against the possibility of unauthorized access to data. Rights review scans identify "privileged users" and access to sensitive database objects. See [Set up and run a job](#set-up-and-run-a-job) for instructions on setting up a rights review job. |
| Credentials | Use a Credential Test job to validate the credentials of audit or rights review jobs. |
| Discovery | You can use a discovery job to check periodically for unknown database instances, or when first setting up the assets in your system. |

### Set up a credential test job

A credential test job performs a test of the credentials you have added to the assets of any other job type.

To create a credential test job:

1. Click **New Job** | **Credential Test** on the **Jobs** tab. The **Create a Job** dialog opens.
2. Type a **Job Name** and select the **Organization** that contains the job you want the credentials test to be run against.
3. Click **Continue**. The **Edit Job** dialog opens.
4. Select the **Job** containing the assets with credentials you want to test.
5. Click **Next** on the **Advanced Settings** side tab.
6. Provide email addresses to be notified at job completion.
7. Select the **Treat missing permissions as fatal** option to indicate whether the job should report a failure if some credentials are valid for connection but missing required permissions for the job tasks.
8. Click **Save**. The job is set up and now appears in the **Jobs** list.
9. Click **Run Now** to run the job immediately.
10. Click **Schedule** and select the **Schedule Type**, **Start Time**, and **Start Date**, to run the job in the future (one-time or recurring).

### Set up a discovery job

To create a discovery job:

1. Click **New Job** | **Discovery** on the **Jobs** tab. The **Create a Job** dialog opens.
2. Type a **Job Name** and select the **Organization** that contains the assets you want to discover.
3. Click **Continue**. The **Edit Job** dialog opens.
4. On the **Discovery Criteria** side tab, click **Add Criteria**. The **Add Discovery Criteria** dialog opens.
5. Enter **Network Destinations**. For examples, see the text and link below the field.
6. Select **Port Options**.
   1. Select **Add defaults** to check the default ports for database types.
   2. Select **Add specific ports** if you know that your organization's databases listen on nonstandard ports.
   3. Select the **Bypass port scanning** option if scanning is not possible in the environment.
   <Warning>
     **Caution:** This option can cause discovery to be less efficient.
   </Warning>
7. Select the checkbox next to at least one **Asset Type**, or the checkbox next to **Asset Types** to select all items.
8. Click **Add**. Repeat previous steps to add additional criteria to the job.
   * Select an existing criteria and click **Edit** to change criteria details.
   * Select an existing criteria and click **Delete** to remove it from the job.
9. Click **Next** or click the **Reports** side tab to set up one or more reports to run as part of this job.
   1. Click Add Report.
      <Note>
        **Note:** For Discovery jobs, only the **Other** report scope is available.
      </Note>
   2. Select a **Report Template** (**Asset Inventory** is commonly selected for discovery jobs), or select the **Filter Shortcut** option and paste a shortcut string into the field.
   3. Click **Change scope organization for this report** to run the report on a descendant (child) organization to reduce the scope of data reported on.
   4. Click **Next** and select an **Organization** for the report to be run on.
   5. Click **Next** and set the **Input Settings**.
   6. Click **Next** and set the **Output Settings**.
   7. Click **Save**.
10. Click **Next** or click the **Advanced Settings** side tab and:
    1. Provide email addresses to be notified at job completion, or if credential problems occur.
    2. Add one or more **Known database/instance/SID names**.
       <Note>
         **Note:** This option can help to find databases if security restrictions are in place, such as SQL Browser being stopped.
       </Note>
    3. Add one or more Oracle listener passwords.
    4. Select the Scan unresponsive hosts option (hosts that do not respond on closed ports) if you want to ensure full results. This will likely increase the time to complete a Discovery job.
    5. Select the Save additional information option to save any data gathered as asset attributes
    6. Select the Update asset version and platform… option if you want an existing asset to be updated if newer versions are available.
    7. Select the Ignore duplicates and errors option to reduce the time to complete the scan
    8. Select the **Replace existing endpoints with discovered ones** option to update existing endpoints that have changed since being added to your assets.
11. Click **Save**. The job is set up and now appears in the Jobs list.
12. Click **Run Now** to run the job immediately.
13. Click **Schedule** and select the **Schedule Type**, **Start Time**, and **Start Date**, to run the job in the future (one-time or recurring).

### Set up a report job

Apart from the built-in on demand reports available on the **Reports** page, you can also set up regularly scheduled report jobs.

To set up a report job:

1. Click **Jobs** page | **Jobs** | **New Job**. The **Create a Job** dialog opens.
2. Select the **Report** job template in the left pane, type a **Job Name**, and select an **Organization** for the job to run on.
3. Click **Continue**. The **Edit Job** dialog opens.
4. Click **Add Report**. The **Report Wizard** opens.
5. Select a **Report Template** or select the **Filter Shortcut** option to create a custom report and paste a shortcut string into the field.
6. Click **Change scope organization for this report** to run the report on a descendant (child) organization and reduce the scope of data reported on.
7. Click **Next** and set the **Input Settings**. Depending on the report template you chose, there may be additional options to complete. For example, in some reports you will need to:

   1. Select an organization for the report. You can choose the organization specified in the job, or an available descendant (child). Click the **Include descendants** option if you want all child organizations to be included.
   2. Select an asset to report on and a specific user to report on.
   3. Choose to include non-scannable assets. Non-scannable assets may include Oracle Listeners and SQL Redirects.
   4. Specify the results filtering and scope of the report.

   <Note>
     **Note:** When reports are generated at the scope of an organization, all check results for all assets in the organization are considered. These results are first filtered by checks that are available to policies associated with the organization. If different policies include different report filters on the same check, all report filters on each check will be applied.

     It can be useful to limit the report to specific assets, or to report on check results based on a specific policy or even a specific audit job. When reports are filtered through a specific policy ("Policy Lens"), only the checks from that policy are included and the report filters specified in that policy are applied.
   </Note>
8. Select a type of filtering, and then select the detailed values. For example:
   * In the **Check Results Summary**, you can choose to filter by assets, attributes, or a specific job, or an organization.
   * You can also choose to filter through a specific Audit or Pen Test policy ("Policy Lens").
   * You can choose to include SHATTER Knowledgebase articles in the report.
9. Click **Next** and set the **Output Settings** for the report.
   1. Enter a **Report Name** and select an output **Format**.
   2. **(OPTIONAL)** Enter the email addresses of users who should receive a link to the completed report.
   3. Click **Save** to add the report to the list.
10. Click **Next** or click the **Advanced Settings** side tab.
11. Add the email addresses of users who should receive a notification when the job is complete.
12. Click **Save**. The job is set up and now appears in the Jobs list.
13. Click **Run Now** to run the job immediately.
14. Click **Schedule** and select the **Schedule Type**, **Start Time**, and **Start Date**, to run the job in the future (one-time or recurring).

### Add assets to jobs using saved and ad hoc queries

To add assets to jobs using saved and ad hoc queries:

1. Create the job (see [Set up and run a job](#set-up-and-run-a-job)), and when you are ready to add assets select one of the two following selections:
   * **Saved query:**
     1. Click the **Saved Query** option.
     2. Choose a saved query from the list on the left side of the **Assets** side tab. Assets matching the query display in the right pane. You cannot modify the query within the wizard.
     3. To modify saved queries, see [Use saved search queries](#use-saved-search-queries).
   * **Ad Hoc Query:**
     1. Click the **Ad Hoc Query** option.
     2. Select facets and/or enter a search expression in the left pane.
     3. Click **Search**. Assets matching the query display in the right pane.
2. Click **Next** to continue, or click the **Policy** side tab.
3. Continue with the job setup as per [Set up and run a job](#set-up-and-run-a-job).

### Edit a Job

* To edit a job, select it and then click **Edit** in the toolbar. For help with the available settings see the sections on creating a job, above.

### Clone a Job

* To make a copy of a job, select it and then click **Clone** in the toolbar. Cloning does not copy the job schedule. After cloning a job, edit it as required and schedule it if required.

### Delete a Job

* To delete a job, select it and then click **Delete** in the toolbar.

### Monitor job progress

Once a job has been set up and scheduled, you can view its progress through the remaining tabs on the Jobs page:

| Tab | Displays |
| - | - |
| In Progress | All jobs that are currently running in DbProtect.<br />• Click Cancel to cancel a job in progress.<br />• Click Resume to restart a job has been paused due to service restart.<br />• Select a job to view more information in the Details pane. |
| Completed | All jobs that are completed, showing completions and failures for each.<br />• Select a job to see its information in the **Details** pane. Click **Expand Details** to see more information about an individual step of a job.<br />• If a step cannot be completed and the job is not set to skip tasks that require input, the detail status shows **Waiting for Input**. Click to view details.<br />• You can select the action to take (**Retry** or **Skip**) using the menu on the right. If you are able to correct the problem (for instance by updating credentials or scan engines) then click **Retry** to try the step again. If you are unable to correct the problem you can **Skip** the step, but the job will not produce complete results. |
| Scheduled | A chronological list of upcoming jobs.<br />• Choose the View (Next 7 days, Next 30 Days, or set Dates) and click Go to filter the scheduled jobs list.<br />• To remove a job from the schedule, return to the Jobs tab, select the job, and click Un-Schedule. Confirm you want to un-schedule the job.<br />• Click the down arrow next to column headings to sort and organize the scheduled jobs list. |

## Advanced Monitoring

<Note>
  **Note:** DbProtect Explorer now offers direct access to Alerts. See [Working with DbProtect Explorer Alerts](#working-with-dbprotect-explorer-alerts) for information about using this new feature.
</Note>

### Alerts tab

On this tab of the **Monitoring** section, you can review alerts generated by monitoring sensors.

* Click any column heading to sort the list.
* Click the **Alert ID** number to view details of an alert.
* Select the checkboxes of one or more alerts to perform the actions on the buttons at the bottom of the list.

#### Refresh alerts

There are a number of options for refreshing alerts:

* Click the **Refresh** button to manually refresh the alert list.
* To refresh automatically, set a time in seconds and click **Start**. To stop refreshing, click **Stop**.
* To change the auto-refresh interval while it is running, enter a time in seconds and then click **Update**.

#### Filter alerts

There are several options for filtering the list of alerts displayed so you can focus on the criteria that are the most urgent or important.

* To filter the alerts shown in the list, make selections from the menus and/or enter parameters in the fields and click **Apply Criteria**.
* Type a number in the **Count** field to view only a set number of alerts at a time.
* Type in the **Search in SQL Text** field to search for the specific SQL query that executed and triggered the alert.

#### Viewing alert details

* Click the **Alert ID** number for an alert to view its information. The details will be displayed in a separate browser window and provide a full listing of all available information about the alert.
* Click **Archive** or **Acknowledge** to process this alert from the detail window or close the window to return to the full list of alerts.

See [Create exceptions](#create-exceptions) for information about creating an exception based on the alert. An exception is a filter that closely matches the alert. The exception will be available to add to policies.

#### Acknowledge and archive alerts

Acknowledging an alert indicates that you have reviewed it.

* Click the **Hide Acknowledged** option if you want acknowledged alerts to be automatically hidden from the active list of alerts.
* Archiving an alert moves the alert to the **Archive** tab and acknowledges the alert if it has not yet been acknowledged.

To acknowledge or archive alerts:

1. Filter the alerts as desired.
2. Click **Archive All Alerts** or **Acknowledge All Alerts** to archive or acknowledge all alerts shown. All displayed alerts will be removed from the list, and if you chose to archive the alerts, they will be moved to the **Archive** tab.

   **OR**

   Select the checkboxes next to one or more alerts that you want to acknowledge or archive and click **Archive Selected Alerts** or **Acknowledge Selected Alerts**. The selected alerts will be removed from the list and if you choose to archive the alerts, they will be moved to the **Archive** tab.

<Note>
  **Note:** You can also perform these actions for a specific alert from the detail window.
</Note>

#### View archived alerts

* Click the **Archive** tab on the **Alerts** page to view the list of alerts that have been archived.

#### Un-archiving alerts

1. Click the **Alert ID** next to an archived alert. The **Details** window opens.
2. Click **Un-archive** to restore the selected alert(s) from the archive to the active list.

#### Delete alerts

<Note>
  **Notes:**

  * You can only delete alerts from the Archive list and not from the active alerts list.
  * Deletion is permanent.
</Note>

To delete archived alerts:

1. Filter the alerts as desired.
2. Click **Delete All Archived Alerts**. All alerts displayed will be permanently deleted from DbProtect.

   **OR**

   Select the checkboxes next to one or more alerts and click **Delete Selected Archived Alerts**. The selected alerts will be deleted from DbProtect.

### Monitoring Dashboard tab

The Monitoring Dashboard shows sensor health and alert status at a glance.

**Sensors' Health**

This section shows the number of registered sensors. If any sensors are not responding to the console a list of details displays. For the most accurate information about unresponsive sensors, see the Alerts tab.

**Unacknowledged Security Alerts**

This section includes two graphs. One shows the total number of unacknowledged alerts, and the other shows the number of unacknowledged alerts received today.

**Informational Alerts**

This section shows the number of informational alerts received today.

### Monitoring Reports tab

In this version of DbProtect, all reports are managed from the **Report** section of the main user interface.

To generate on-demand reports of monitoring activity, see **Report** | **On Demand** | **Monitored Events**.

### Monitoring Policies tab

This tab allows you to manage and deploy monitoring policies for sensors. A monitoring policy is a collection of rules or activity monitoring checks. LevelBlue provides several default monitoring policies, and you can also import or create your own policies to meet your organization's security requirements.

<Note>
  **Note:** These policies are used for monitoring sensors and are managed separately from the vulnerability policies applied during the job setup.
</Note>

The column **Deployment Count** indicates the number of sensors where the policy is deployed. Policies marked with \* are "stale", which identifies an updated policy that has not been deployed.

#### Create a policy

To create a policy:

1. Click **Create New Policy**. The **DbProtect Activity Monitoring Policies** page opens in a new browser window and displays a hierarchy view of available policy rules.
2. Expand the tree to see available rules for each server type and category.
3. Click the rule name to view details of the threats or behaviors covered in the right pane.
   <Note>
     **Note:** Exceptions that you have created are displayed in the hierarchy as branches below (within) the rule that you created an exception to. See [Create exceptions](#create-exceptions) for information about creating exceptions.
   </Note>
4. Select the checkboxes next to each rule that you want to include in your policy.
5. Set the **Risk Level** for each rule using the menu for that rule (displayed at the end of the rule name).
6. When you have completed your selections, enter a name for the policy at the top of the rules list and click **Save**. The new policy is displayed in the list on the **Monitoring** | **Policies** tab and is available for deployment.

#### Edit a policy

To modify a policy:

1. Click the **Edit** button next to a named policy in the list. The **DbProtect Activity Monitoring Policies** page opens in a new browser window.
2. Expand the tree to see available rules for each server type and category.
3. Click the rule name to view details of the threats or behaviors covered in the right pane.
4. Select the checkbox next to each rule that you want to include in your policy.
5. Set the **Risk Level** for each rule using the menu for that rule (displayed at the end of the rule name).
6. When you have completed your selections:
   * If you edited a custom policy that you had previously created, click **Save** to save changes, or enter a new name and click **Save As** to save a new policy and keep the existing policy.
   * If you edited a built-in policy, you can only **Save As** (you cannot change built-in policies). The new policy is displayed in the list on the **Monitoring** | **Policies** tab and is available for deployment.

<Note>
  **Note:** After editing a policy that is deployed, you must re-deploy the policy to apply any changes to sensors.
</Note>

#### Delete a policy

* Click **Delete** next to a policy that you created to delete it. Built-in policies cannot be deleted.

You cannot delete a policy that is deployed. Before deleting a policy, "un-deploy" it by deploying a different policy to any sensors where you were using it.

#### Export and import a policy

To export a policy:

1. Click the **Export** button for the policy in the list.
2. Navigate to the location where you want the resulting XML file to be located and click **Save**.

To import a policy:

1. Click **Import Policy**.
2. Click **Choose File** and navigate to the location where you have previously saved a valid policy XML file.
3. Select the file and click **Open**. The file name is displayed next to the **Choose File** button.
4. If you want to overwrite an existing policy with the same name as the one you've selected, select the **Import with overwrite** option.
   <Note>
     **Note:** The file name is not the policy name. The policy name is found within the file.
   </Note>
5. Click **Import**.

#### Re-deploy multiple policies

This feature can re-deploy multiple different policies that were already deployed to various sensors. For example, you may want to re-deploy multiple updated policies to sensors where the policies are out of date. This differs from deploying a single policy to multiple sensors, which is what occurs when you deploy from the Policy Manager page.

To re-deploy the currently configured policies on more than one sensor:

1. Click **Deploy Policies in Bulk**. The **Policy Deployment** page opens and displays a list of sensors and the policies that have been deployed to them.
2. On the **Policy Deployment** page, the list of **available database applications** shows configured Sensors and the currently deployed policy for each (if any).
   * Type in the **Search** field to look for specific text in the descriptions of the sensor
   * Select the **Only show databases with stale policies** to limit the list to sensors that require updated policies.
3. Select one or more items and use the arrows to move the selected items into or out of the **Re-deploy policies to** list.
4. Click **Deploy** to re-deploy selected policies to the sensor(s). Deployment success or failure will be confirmed on this page.

### Filters

This tab allows you to create and manage filters that can be included in monitoring policies.

Filters allow you to create exceptions to rules and alerts and allow you to create rules specific to your environment (for instance, to monitor a specific function or procedure).

#### Create audit filters

1. Under **Audit Filter Wizard**, click **Create**. The **Filter Manager** page opens.
2. Select the database type and click **Next**. The **Audit Filter Wizard** opens.
3. Select one or more types of actions to audit, and then click **Next**. Available actions include:
   * SELECT, INSERT, UPDATE, and DELETE actions on user and system tables and views
   * EXECUTION of Stored Procedures and Functions
4. Select the **Database Instance** to audit from the drop-down list and click **Next**.
5. Select the **Database** to audit from the drop-down list and click **Next**.
6. Select the object(s) to audit. To select multiple items, press `Ctrl` while selecting the items, or click and drag your mouse down the entire list to select all items.
   * For any tables selected in the list, select **Yes** or **No** to indicate whether to audit on the column level.
   * Select one or more stored procedures and functions that you would like to audit.
7. Click **Next**. The following page of the Audit Filter Wizard may take a few moments to load, depending on the number of items selected on the previous page.
8. If you choose to audit on the column level, select the columns to audit (for each table you selected) and click **Next**.
9. Type a **Title** and other descriptive information for the audit.
10. Select a **Risk Level** from the drop-down list and click **Next**.
    <Note>
      **Note:** Items with **Info-\[#]** selected for **Risk Level** do not display in detail in the console.
    </Note>
11. Review the details of your audit filter. Click **Back** to make changes or **Save** to create the filter.
12. Click **Add filter to policy** to go to the **Policy Manager** page.
13. Click **Edit** next to the policy you want to add the newly created filter to. The **DbProtect Activity Monitoring Policies** page opens in a new window.
14. Expand the tree for the database type you selected when creating the filter, then expand **Audit Events**.
15. Scroll down the list and expand the **User \[action or function]** item that matches the selection you made when creating the filter (e.g., "User Table – Select" or "User defined function")
16. Select the checkbox next to the filter you created and:
    * If you edited a custom policy that you had previously created, click **Save** to save changes, or enter a new name and click **Save As** to save a new policy and keep the existing policy.
    * If you edited a built-in policy, you can only **Save As** (you cannot change built-in policies).

#### Create exceptions

To create an exception:

1. Under **Exception Wizard**, click **Create**. The **Filter Manager** opens.
2. Select the database type and click **Next**. The **Exception Wizard** opens.
3. From the **Create an exception for the rule** drop-down list, select a rule. If you want to create a Global Exception (not limited to specific rules), select **All \[database type] Activity**.
4. Click **Next**.
5. Add one or more conditions that define the situations where the parent rule should not fire.

   <Note>
     **Notes:** If you add more than one condition, the exception will only apply when ALL conditions are true.

     * To make exceptions for several different single conditions, the preferred method for readability is to create an exception for each condition.
     * You can also edit the expression using the **Advanced Filter and Exception Editor** and change the `<and>` condition to `<or>`.
   </Note>
6. Type a **Title** and other descriptive information for the audit and click **Next**.
7. Review the details of your exception filter. Click **Back** to make changes or **Save** to create the filter.
8. Click **Add to policy** to open the Policy Manager page.
9. Expand the tree for the database type you selected when creating the filter, then expand the tree further to find the parent rule that you created the exception for.
   <Note>
     **Note:** Some rules, such as "All Microsoft SQL Server 2005/2008/2012/2014 Activity" will result in your exception being placed in the **User-defined Global Exceptions** folder.
   </Note>
10. Select the checkbox next to the filter you created and:
    * If you edited a custom policy that you had previously created, click **Save** to save changes, or enter a new name and click **Save As** to save a new policy and keep the existing policy.
    * If you edited a built-in policy, you can only **Save As** (you cannot change built-in policies).

#### Create advanced filters and exceptions

1. Under **Advanced Filter and Exception Wizard**, click **Create**. The **Filter Manager** opens.
2. Choose the database type and click **Next**. The **Advanced Filter Editor** opens.
3. Select the rule that you want to create the filter or exception for. If you want to create a global exception or filter (not limited to specific activity types), select **All \[database type] Activity**.
4. Click **Next**.
5. Select whether to trigger ONLY when the conditions are met or EXCEPT when the conditions are met.
6. Enter expressions and conditions that define the filter.

   The filter is saved in an XML document and must be valid XML

   * Each expression consists of a name, an operator, and a value. The Legend shows available operators and some common names.
   * For a full list of names, see [Appendix A: Monitoring Filter Name Attributes](#appendix-a-monitoring-filter-name-attributes).
   * Expressions can be combined using the operators AND and OR.

   <Note>
     **Note:** The expression editor performs some basic checking of the XML format and the contents of the expressions. The editor does not check for valid tag names.

     A good way to understand the format of filters is to create some filters or exceptions using the wizards, and then edit them in the Advanced Filter and Exception Editor to see how the information is saved
   </Note>
7. Click **Next**.
8. Type a **Title** and other descriptive information for the audit.
9. Select a **Risk Level** from the drop-down list and click **Next**.
   <Note>
     **Note:** Items with **Info-\[#]** selected for **Risk Level** do not display in detail in the console.
   </Note>
10. Review the details of your filter. Click **Back** to make changes or **Save** to create the filter.
11. Click **Add to policy** to open the **Policy Manager** page.
12. Expand the tree for the database type you selected when creating the filter, then expand the tree further to find the parent rule that you created the filter for.
    <Note>
      **Note:** Some rules, such as "All Microsoft SQL Server 2005/2008/2012/2014 Activity" will result in your exception being placed in the **User-defined Global Filters** folder.
    </Note>
13. Select the checkbox next to the filter you created and:
    * If you edited a custom policy that you had previously created, click **Save** to save changes, or enter a new name and click **Save As** to save a new policy and keep the existing policy.
    * If you edited a built-in policy, you can only **Save As** (you cannot change built-in policies).

**Available Filter Operators**

| Operator | Usage |
| - | - |
| Equals | Performs a case sensitive string comparison of the value and the named element. The value must match exactly. |
| notEquals | Performs a case sensitive string comparison of the value and the named element. The value must NOT match exactly |
| Equivalent | Performs a NON-case sensitive string comparison of the value and the named element. The value must match exactly, but letter case is ignored |
| notEquivalent | Performs a NON-case sensitive string comparison of the value and the named element. The value must NOT match exactly, and letter case is ignored |
| containsCase | Performs a case sensitive string comparison of the value and the named element. The value must be found anywhere in the element |
| notContainsCase | Performs a case sensitive string comparison of the value and the named element. The value must NOT be found anywhere in the element |
| Contains | Performs a case sensitive string comparison of the value and the named element. The value must be found anywhere in the element, and letter case is ignored |
| notContains | Performs a case sensitive string comparison of the value and the named element. The value must NOT be found anywhere in the element, and letter case is ignored |
| Like<br />notLike | Performs a string comparison (not case sensitive) of the value and the named element. Supports two wildcards:<br />• `%` (matches zero or more characters)<br />• `_` (matches exactly one character) |
| Regex<br />notRegex | Treats the value as a Regular Expression test (not case sensitive) that is applied to the named element.<br />Regular Expression matching provides powerful searching abilities but would rarely be required. As a starting point for help with Regular Expression syntax, see Wikipedia or other online sources. |
| lessThan<br />lessThanEqual<br />greaterThan<br />greaterThanEqual | Performs an integer comparison of the value and the named element. You cannot apply these operators to alphabetic values or real numbers. |

#### Edit a filter

* Click **Edit** next to the filter you want to modify. The item will be opened for editing in the **Advanced Editor Wizard**. Make changes as required and click **Save**.

<Note>
  **Note:** If the filter is active in any policies, you must re-deploy the policies to apply your change on the sensors. Policies that require deployment are marked as "stale" on the **Policy Manager** tab.
</Note>

#### Delete a filter

<Note>
  **Note:** You cannot delete a filter that is actively used in a policy. If you attempt to delete an active filter, you will be informed of the policy or policies where it is used.
</Note>

* Click **Delete** next to the filter or exception you want to remove. You will be asked for confirmation.

#### Import a filter

To import a file containing filters:

1. Under **Import Filters**, click **Import**.
2. Click **Choose File** and navigate to the location where you have previously saved a valid policy XML file.
3. If you want to overwrite existing filters with the same names as filters found in the file, select the **Import with overwrite** option.
   <Note>
     **Note:** The file name is not the filter name. The filter name(s) is found within the file.
   </Note>
4. Click **Import**.

#### Export a filter

1. Select one or more checkboxes beside the filter you want to export from the **My Filters** list. To select all items, select the checkbox under the **Export** button.
2. Click **Export**.
3. Navigate to the location where you want to save the resulting XML file and click **Save**.

### Sensors tab

This tab allows you to register and configure sensors. For full information about installing and configuring sensors see the *DbProtect Sensor Installation and Configuration Guide*.

The main page of the **Sensors** tab lists all registered sensors in the left pane and shows the status of each sensor.

#### View sensor details

1. Select a sensor name in the left pane to view details in the right pane. Sensors that cannot be contacted or that have a configuration issue display a warning icon.
2. If many sensors are configured, type text in the **Filter** field and click **Apply**.
3. Click **Refresh Status** to make sure you are looking at an accurate list of available sensors.

#### View sensor configuration details

1. Click **View Sensor Configuration Details** to view a summary of configuration for all sensors. The **Configuration Summary** page lists the availability, network location, version, database instance monitored, and policy deployed for each sensor alias.
2. Click **Download CSV** to download the information to file you can save.
3. Click **Back** to return to the main page.

#### Configure or reconfigure a sensor

To configure or reconfigure database instances on an installed sensor:

1. Select the sensor in the left pane to view details in the right pane.
   <Note>
     **Note:** You cannot reconfigure a sensor that cannot be contacted.
   </Note>
2. Click **Reconfigure** to display the details of the configured instances on the sensor.
   * Click **Reconfigure** next to a defined instance. For detailed procedures, see the *DbProtect Sensor Installation and Configuration Guide*.
   * Click **X** next to a defined instance to remove it from the list of configured sensors.
   * Click **Configure New Instance** to configure a new instance of the sensor. For detailed procedures, see the *DbProtect Sensor Installation and Configuration Guide*.
3. Under **Advanced Settings**, click **Modify** to change the logging level for the sensor.
4. Select a different logging level from the drop-down list and click **OK**.
5. When you have completed all required changes, click **Deploy to Sensor**.

<Note>
  **Note:** If you do not deploy the changes, they will be lost.
</Note>

#### Unregister a sensor

Unregistering stops sensor activity for all database instances configured on that sensor and removes the connection between the console and the sensor.

To unregister a sensor:

1. Select the sensor in the left pane to view details in the right pane.
2. Click **Unregister**. You will be asked for confirmation.

<Note>
  **Note:** Unregistering does not uninstall the sensor software. After unregistering you should proceed to uninstall the software from the server where it is installed.
</Note>

#### Deploy multiple policies

To re-deploy multiple policies to sensors, click **Deploy Policies in Bulk**, then refer to [Re-deploy multiple policies](#re-deploy-multiple-policies) for further instructions to complete this task.

### Monitoring Settings

There are three sub-tabs for the **Monitoring Settings** feature, allowing you to set the following for automated monitoring communications within DbProtect:

* Email forwarding rules
* Forwarding settings
* Email server settings

#### Email Forwarding Rules

Define alerts that you want DbProtect to report to users by email. Available actions are listed on the page.

<Note>
  **Note:** If no rules are defined, the first page of the rule creation wizard displays as the default item of the tab.
</Note>

##### Create or modify an email forwarding rule

1. Click **Create a new Email Forwarding Rule** (below the existing rules list, if any).

   **OR**

   Click **Modify** next to an existing rule that you want to change.
2. On the first page of the **Email Forwarding Rules Wizard**, type or modify **Template Name** for the rule and type (or paste) a list of email addresses to send activity notifications to. Addresses should be comma-separated; the entire list cannot exceed 256 characters.
3. Click **Next**.
4. On the criteria page of the wizard, select:
   * One or more server aliases (`Ctrl`-click to select more than one; click **ALL** to select all)
   * One or more alert titles (`Ctrl`-click to select more than one; click **ALL** to select all)
   * A time range (any time, or a start and end time in 24-hour format)
   * One or more risk levels
5. Click **Next**.
6. On the fields page of the wizard, select one or more fields to include in the message, and use the arrow buttons to move them between the **Possible Fields** and **Fields to Send** boxes.
7. Click **Next**.
8. On the summary page of the wizard, review the rule.
9. Click **Back** to make changes or **Save** to save the rule. New rules are active by default.

#### Forwarding settings

Specify settings for email alerting checks:

* **Polling Frequency:** Enter the number of minutes between checks by DbProtect for new alerts that match the forwarding rules. The default polling frequency is 5 minutes.
* **Maximum Alerts to Handle:** Enter the maximum number of alerts you want DbProtect Activity Monitoring to send in each email.

#### Email server settings

Email server settings are now managed in **Settings** | **Email**.

## Working with DbProtect Explorer Alerts

The **Alerts** tab functionality that is available in DbProtect Core is being replaced and expanded in DbProtect Explorer. The new **Alerts** tab provides the same easy access to active and archived alerts and displays alerts that have already been acknowledged.

Beginning with DbProtect Explorer v6.6.1, there is also an early preview of the new **Anomalies** tab, where you can view anomaly alerts generated by machine learning (ML) developed from the standard DbProtect sensor data. The **Anomaly Detector** analyzes existing sensor data to learn database access, login, and use patterns, and then generates anomaly alerts based on deviations from those patterns.

Alerts generated by the DbProtect sensors are displayed on the **All Alerts** tab on the Alerts page.

To filter the alerts list:

1. Select a timeframe from the drop-down list at the top of the filter pane.
2. Indicate whether you want to show **Archived** or **Acknowledged** alerts in the list.
3. Select the level(s) of **Risk** you would like to filter the list with.
4. Click **Update Search**. The list is updated.
5. Select an alert to view its initial details in the bottom pane or double-click to view full information.

### Archive or Acknowledge alerts

To archive or acknowledge alerts:

1. Select the checkbox next to each alert you want to archive or acknowledge, or select the checkbox at the top of the column to select all items.
2. Click the **Archive** or **Acknowledge** button, as required.

### Filter Anomalies (Preview)

Anomalies are specialized machine learning-based alerts that represent variations from typical user and/or system activity. They are represented in the **Anomalies** pane with one of two icons:

* Anomaly
* First-seen anomaly (reverts to the Anomaly icon if the same alert is raised more than once)

To filter anomalies:

1. Select a timeframe from the drop-down list at the top of the filter pane.
2. **(OPTIONAL)** Click the add condition icon to apply further conditions to the list using either "contains" or "does not contain" criteria.
3. Click **Update Search**. The list is updated.
4. Select an alert to view initial details in the bottom pane, or double-click for full information.

## Working with Reports

DbProtect provides a large number of reports. New reports might be added when you update the Analytics Content. You should always update to the latest available version of Analytics Content to ensure that you have the most up-to-date reporting functionality.

<Note>
  **Note:** To generate a list of all available reports, including descriptions of purpose and output formats, see [Filtering and Generating Reports](#filtering-and-generating-reports).
</Note>

You can also run reports from a report job, and as part of some other job types. Reports in jobs allow you to select result filtering and scope before running the report. You can access the output of these report jobs from the **History** list on the **Reports** page. You can also choose to send report links by email.

### Filter a report

For information on how to filter reports in the Explorer UI, refer to [Filtering and Generating Reports](#filtering-and-generating-reports).

### Difference between On Demand reports and Job reports

On Demand Reports and Job Reports on the same assets might show different results.

* On Demand reports are generated from the Explorer Dashboard and can be filtered based on various criteria. DbProtect calculates an effective policy based on all policies available to the organization.

  The report output shows the results based on date and other criteria specified.
* When a report is generated as part of a specific audit job, the report output shows only the results from that run of the job. These results will usually have a much more focused, effective policy.

## Modify System Settings

The **System Settings** section of DbProtect Core allows you to review DbProtect system performance, manage licensing and email sending settings, and manage Scan Engine registrations.

### About DbProtect

This page displays a list of components installed locally to the DbProtect server, and components such as scan engines that are remotely installed and registered.

### Scan Engines settings

See [Register a scan engine](#register-a-scan-engine) for detailed instructions for registering scan engines, and [Working with scan engines](#working-with-scan-engines) for information about configuring and unregistering scan engines, and updating the SHATTER knowledgebase.

### Email

Configure an outgoing email server, used by all DbProtect components, to send notification emails.

<Note>
  **Note:** The email server you configure must accept messages:

  * Sent from the **From Address** you specify, and from the network locations of all the DbProtect components
  * Sent to the addresses you specify (normally addresses in your internal organization)
</Note>

You may need to configure the target server to accept these messages.

To add or edit the email server information:

1. Click **Edit**. The **Outgoing Email Server Settings** dialog opens.
2. Enter the IP address or resolvable name of the **SMTP Server**.
3. Enter the **Port** number where mail is accepted (normally port 25).
4. If a login is required to send mail, enter the **User Name** and **Password**.
5. **(OPTIONAL)** Select the **Set a limit for email attachments** option and type a maximum size in MB to limit the size of email attachments (such as PDF report files).
6. **(OPTIONAL)** Enter addresses in the **From** and **Reply-To** fields. If these fields are left blank, the messages will be sent with a blank From Address.
7. If you want to send a test email (recommended):
   1. Click Send test email.
   2. Type the address in the **Test Email Address** field.
   3. Click Send Test Email. The dialog that opens shows whether the message was sent. If the message could not be sent, a new window displays the error.
8. To save the configuration, click **OK**.

<Note>
  **Note:** DbProtect does not prevent saving of an invalid configuration. Test carefully.
</Note>

### Diagnostics

This tab displays information about the status of DbProtect components.

### Warehousing

This tab allows you to view the status of data synchronization and warehousing, and to start a manual update or warehousing window.

* Click **Update Now** to push stored updates to your assets, organizations, and policies, without waiting until the scheduled warehousing window starts.
* Click **Get data warehouse statistics report** to generate a statistical report on the job activities run on your network.
* Click **Show Advanced Options** | **Start Window Now** to manually start a warehousing window. All updates to the system from the point forward are published as they occur. If you want to end the window before the updates are complete, click **End Current Window**.

### Licensing

This tab displays the details of licensing for this DbProtect installation. For more information about licensing, refer to the *DbProtect Installation and Upgrade Guide*.

To add a license:

1. Click **Add License** to open the **Add A License** dialog.
2. Type or paste the contents of the `ARxx.lic` or `ADxx.lic` file in the field, and then click **Add**.
3. Click **Get license utilization report** to see a report of license utilization by asset, organization, and usage details.

## Appendix A: Monitoring Filter Name Attributes

### Name Attributes

The following table includes valid DbProtect name attributes, which are common for all Activity Monitoring expressions across all supported database platforms.

**DbProtect Name Attributes**

| DbProtect Name Attribute | Details |
| - | - |
| Application | Name of the client application that created the connection to an instance of a given database type (i.e., Microsoft SQL Server, DB2, Sybase, or Oracle). This column is populated with the values passed by the application rather than the displayed name of the program. |
| ColumnName | The name of the column of a table in which the user statement is running. |
| DbUser | Database username. |
| HostName | The name of the machine (host) from which the client application is run. |
| ObjectName | Name of the referenced object. |
| SqlText | The SQL text command presented for execution by the client. |
| AbsDate (yyyy/mm/dd) | Absolute date. |
| DayOfWeek | Date (month and date). |
| Date (mm/dd) | Date (month and date). |
| TimeOfDay (hh:mm) | Time of day in 24-hour time (e.g., 20:00 = 8 P.M.). |
| RecordsAffected | Indicates how many rows have been queried/updated after executing a SQL statement. |

### SQL Server Name Attributes

The following table includes valid Microsoft SQL Server name attributes (for Microsoft SQL Server). An expression can contain SQL Profiler Data Columns, and DbProtect Activity Monitoring-defined values.

**SQL Server Name Attributes**

| SQL Server Name Attribute | Details |
| - | - |
| ClientProcessID | ID assigned by the host computer to the process where the client application is running. This data column is populated if the client process ID is provided by the client. |
| DatabaseName | Name of the database in which the user statement is running. |
| Error | Indicates if the SQL command yielded an error. |
| EventSubClass | Type of event subclass, providing further information about each event class. For example, event subclass values for the Execution Warning event class represent the type of execution warning:<br />1 = Query wait. The query must wait for resources (for example, memory) before it can execute.<br />2 = Query time out. The query timed out while waiting for required resources to execute. This data column is not populated for all event classes. |
| NestLevel | The nesting level of the stored procedure call. For example, my\_proc\_a stored procedure calls my\_proc\_b. In this case, my\_proc\_a has a NestLevel of 1, my\_proc\_b has a NestLevel of 2. |
| NTUserName | Windows NT 4.0 username. |
| ObjectOwner | User who owns the referenced object. |
| ObjectType | Value representing the type of the object involved in the event.<br /><br />Values for Microsoft SQL Server 2000:<br />• 1 = Index<br />• 2 = Database<br />• 5 = Default<br />• 8 = Stored Procedure<br />• 9 = Function<br />• 10 = Rule<br />• 12 = System Table<br />• 13 = Trigger<br />• 17 = User Table<br />• 18 = View<br />• 19 = Extended Stored Procedure<br /><br />Values for Microsoft SQL Server 2005 and 2008:<br />• 8259 = Check Constraint<br />• 8260 = Default (constraint or standalone)<br />• 8262 = Foreign-key Constraint<br />• 8272 = Stored Procedure<br />• 8274 = Rule<br />• 8275 = System Table<br />• 8276 = Trigger on Server<br />• 8277 = (User-defined) Table<br />• 8278 = View<br />• 8280 = Extended Stored Procedure<br />• 16724 = CLR Trigger<br />• 16964 = Database<br />• 16975 = Object<br />• 17222 = FullText Catalog<br />• 17232 = CLR Stored Procedure<br />• 17235 = Schema<br />• 17475 = Credential<br />• 17491 = DDL Event<br />• 17741 = Management Event<br />• 17747 = Security Event<br />• 17749 = User Event<br />• 17985 = CLR Aggregate Function<br />• 17993 = Inline Table-valued SQL Function<br />• 18000 = Partition Function<br />• 18002 = Replication Filter Procedure<br />• 18004 = Table-valued SQL Function<br />• 18259 = Server Role<br />• 18263 = Microsoft Windows Group<br />• 19265 = Asymmetric Key<br />• 19277 = Master Key<br />• 19280 = Primary Key<br />• 19283 = ObfusKey<br />• 19521 = Asymmetric Key Login<br />• 19523 = Certificate Login<br />• 19538 = Role<br />• 19539 = SQL Login<br />• 19543 = Windows Login<br />• 20034 = Remote Service Binding<br />• 20036 = Event Notification on Database<br />• 20037 = Event Notification |
| Permissions | Integer value representing the type of permissions checked. Values are:<br />• 1 = SELECT ALL<br />• 2 = UPDATE ALL<br />• 4 = REFERENCES ALL<br />• 8 = INSERT<br />• 16 = DELETE<br />• 32 = EXECUTE (procedures only)<br />• 4096 = SELECT ANY (at least one column)<br />• 8192 = UPDATE ANY<br />• 16384 = REFERENCES ANY |
| SPID | Server Process ID assigned by SQL Server to the process associated with the client. |
| SQLSecurity LoginName | Name of the login of the user (either SQL Server security login or the Windows login credentials in the form of \[DOMAIN]\\\[Username]). |
| StartTime | Time when the event started, when available. |
| Success | Indicates if the SQL command yielded ran successfully. |
| TargetLoginName | For actions which target a login (for example, adding a new login), the name of the targeted login. |

For more information about SQL Server Profiler Data Columns, see your SQL Server documentation.

### DB2 Name Attributes

The following table includes valid DB2 name attributes. An expression can contain these DbProtect Activity Monitoring-defined values.

| DB2 Attribute | Details |
| - | - |
| DatabaseName | Name of the database in which the user statement is running. |
| OsUser | Name of the login of the operating system user running the database client. |
| SqlTextSize | The size of the SQL text command presented for execution by the client. |

### Sybase Name Attributes

The following table includes valid Sybase name attributes. An expression can contain these DbProtect Activity Monitoring-defined values.

| Sybase Attribute | Details |
| - | - |
| DatabaseName | Name of the database in which the user statement is running. |
| OsUser | Name of the login of the operating system user running the database client. |
| SqlTextSize | The size of the SQL text command presented for execution by the client. |

### Oracle Name Attributes

The following table includes valid Oracle name attributes.

| Oracle Attribute | Details |
| - | - |
| OsUser | Name of the login of the operating system user running the database client. |
| SqlTextSize | The size of the SQL text command presented for execution by the client. |

## Appendix B: User Account Privileges Needed for Audit and User Rights Review Scans

Audit policy scans and user rights review scans require read-only access to the asset. While you can use an administrator account to run the scans, it is not required. To set up the appropriate database access on the assets, User Creation Scripts are provided within the product.

<Note>
  **Note:** Audit of some assets is limited to validation of parameters and OS settings. Audit of these assets only requires access to the OS and parameter files and does not require access to the data store itself.
</Note>

To access these files, proceed to the following directory:

```text theme={null}
<InstallDir>\Trustwave\DbProtect\Resources\ShatterKnowledgebase\UserCreationScripts
```

In the directory, you will see a readme file that provides you more information about each script. The basic guidance is as follows (`[Asset]` is replaced by asset type and version if required):

* **CreateUser**\[Asset]**.sql**: Creates a user called aduser and grants read-only permissions needed to run Audit policy scans
* **CreateUser**\[Asset]**URR.sql**: Creates a user called aduserURR and grants read-only permissions needed to run Audit policy and User Rights Review scans
* **CreatePowerUser**\[Asset]**.sql**: Creates a user called aduser\_admin and grants elevated privileges (for example, SYSDBA for Oracle)
* **CreateUser**\[Asset]**SA.sql**: Specific to Microsoft SQL Server. Creates a user called aduser and grants sysadmin rights

To understand if you should use the PowerUser or SA script, read the `CheckPermissions.txt` file located in the following directory as there are some checks that do require elevated privileges:

```text theme={null}
<InstallDir>\Trustwave\DbProtect\Resources\ShatterKnowledgebase
```

In addition to setting up database access on the asset, OS access may also be needed if you are running OS integrity checks or checks that do require OS access (such as Oracle Critical Patch Update checks). See the readme file for complete instructions on setting up WMI and DCOM permissions. Beyond the information in the readme file, the following provides additional guidance on OS access:

**Permissions for Windows OS Access**

| Check | Windows permission needed |
| - | - |
| Not Using NTFS Partition | Permission to read the installation disk type |
| Registry Permissions | Remote registry access |
| Service Runs as Local System | Permission to list the system services |
| Permissions on Files | Permission to read files in the installation directory of the database. |
| Parameter checks | Permission to read files in the installation directory of the database. |

**Permissions for Unix OS Access**

| Check | Unix Permission Needed |
| - | - |
| Permissions on Files | Permission to read files in the installation directory of the database. |
| Setgid Bit Enabled | Permission to read files in the installation directory of the database. |
| Setuid Bit Enabled | Permission to read files in the installation directory of the database. |
| Parameter checks | Permission to read files in the installation directory of the database. |

Certain target databases require you to set system variables to specify the location of the database instances.

**Target Database Variables for Unix**

| Target Database | Unix Variable Needed |
| - | - |
| Oracle | Make sure the `$ORACLE_HOME` variable is correct.<br />**Note:** The OS account must have privileges of Oracle Software Owner. |
| Sybase ASE | Make sure the `$SYBASE` variable is correct. |
| MySQL | Define a datadir or basedir variable to point to the database root. |

For Microsoft SQL Server, you can also choose to use Windows Authentication for database credentials. You will need to enter the domain or hostname, username, and password. (for example, if your Windows login is `domain\aduser`, you enter 'domain' in the **Domain** or **IP/Hostname** field, and 'aduser' in the **User Name** field).

<Note>
  **Notes:**

  * If any fields are encrypted and the account used for the Audit policy scan does not have access to those fields, some checks may not work properly.
  * Depositor access that only has access to read public documents provides sufficient privileges to run an Audit policy, with the exception of the names database, which requires Reader access.
</Note>

## Appendix C: Sensitive Data Discovery (SDD)

### Analyzing Logic

For the Sensitive Data Discovery (SDD) to function, it first needs to analyze the data contained in the target database. This analysis is performed by looking at the database schema for obvious identifiers like a column named "SSN." For further confirmation of the data contained in a column, the scan will sample the first ten (10) rows of data in the table.

<Warning>
  **Caution:** At a minimum, to properly run an SDD audit the user account must have permissions to read the data and the schema.
</Warning>

#### Confidence level analysis

* **Very Low**: when data has multiple types and has no data to verify.
* **Low**: when data has one type and has no data to verify.
* **Medium**: when data has only one type and not all values are verified (null or value has both negative and positive matching)
* **High**: when data has both name and value matches. Most values validated > 50% positive, has no negative matching
* **Very High**: when data has both name and value matches, and has other related data in the same table or related tables by foreign keys

#### Sensitivity level analysis

The base sensitivity level is defined by the initial type of sensitive data itself. The analyzer will adjust the sensitivity level based on the relationship between the data. Data is related if they belong to a table or related tables by foreign keys.

For example, if there are two tables in a database that are related by foreign key, let us call them "user" and "contact". These are first identified by the base sensitivity type of the individual data type. The "user" table has the primary key "id" to identify a user, and it also has the column "LastName". In the second table a "contact" database exists and the column "userId" is defined as a foreign key point that points to column "id" of the table "user". The second table also defines the address and phone number. Because of the foreign key being defined, the contact information of a customer or user can be identified. For that reason, the sensitivity of the two tables is high, and the columns containing those data types are considered highly sensitive. If there is no foreign key defined, we can have many "LastName" and "Address" columns, but they are disjoined, and the sensitivity is lower.

<Note>
  **Note:** Sensitive level and Confidence level are independent attributes. Sensitive level can be high even if the confidence level is low and vice versa.
</Note>

### SDD reporting

Within a group of sensitive data, the highest confidence level of a sensitive data type will be reported. The lower confidence ones will be dropped.

## Appendix D: Maintenance and Disaster Recovery

### Maintenance Topics

DbProtect has very little need for routine maintenance. Most maintenance is required due to changes in the environment or an unplanned growth of consumed resources. The typical areas of maintenance are highlighted below.

| Maintenance Task | Description |
| - | - |
| Networking | DbProtect suite components should be treated in the same class as production databases and application servers. In DHCP environments, the addresses must be reserved. Failing to do so might lead to some components losing communication with others when the underlying host restarts and gets new network addresses. |
| Disk Growth & Starvation | There are a number of elements that lead to growth of disk usage on the application server. Primarily, this is from the storage of finished reports and the use of %TEMP% directories during report generation. When a host runs low on disk, reports might start to fail, and the host may slow down overall while the operating system is attempting to use disk. |
| SQL Server Repositories | During a fresh install of DbProtect, the databases are created with simple recovery mode. However, it is customary to not use this in production. Once a proper recovery mode has been selected, a maintenance plan should be put in place in order to routinely maintain transaction logs. In addition, the growth of databases due to collected data should be projected, observed and factored into routine expansion planning. |
| Users & Credentials | DbProtect refers to users that are part of the local or domain environment. For the servicing of locked accounts and password changes, the appropriate IT administrator would need to address these, since they are defined outside DbProtect. Although Windows groups may be used to define access, the administration of groups and their membership is also handled outside DbProtect. |
| Certificates & Ciphers | DbProtect uses a built-in web application server. This serves web pages securely.<br />However, a self-signed web server certificate is installed with the product. In order to provide a secure browsing experience, customers should install their own web server certificates that are signed by an authority that will be trusted within their own IT environments. In addition, for SSL communications across components, ciphers may be restricted to ones that are authorized by the IT environment. |
| Licensing | Ensure that you have a valid DbProtect license. In the absence of this, you will not be able to use all product functions. |
| Virtualized Resources | With the increased use of virtualized environments, resource starvation commonly occurs due to an over subscription of available resources, and/or restrictions in access to disk or network resources. Lingering reports of performance degradation warrants a closer inspection of the provisioning of virtualized environments. |
| Contacting Support | You are welcome to contact LevelBlue Technical Support for any questions or concerns arising from operation of the product. For the various ways to contact us, please visit [https://www.levelblue.com/company/support](https://www.levelblue.com/company/support). |

### Backup and Disaster Recovery

The approaches for backup and recovery vary based on the investment in backup infrastructure and the tolerance of downtime. The different approaches are described below.

| Backup Approach | Description |
| - | - |
| **Hot Backup**<br />Downtime Tolerance: Within the hour | To achieve a near-real time rollover to a hot backup, a complete set of backup hardware for all components is required. In this environment, you will need to set up:<br />• The ability to remap network address and host identity<br />• Live mirroring of repositories with the hot backup database repository<br />• Live disk mirror for the DbProtect application files with hot backup host<br /><br />This approach leads to no data loss during recovery. |
| **Warm Backup**<br />Downtime Tolerance: Same day | To achieve rollover to a warm backup, a complete set of backup hardware for all components is required. In this environment, you will need to set up:<br />• The ability to remap network address and host identity<br />• The ability to take frequent backups of the DbProtect application files and database<br /><br />This approach may have some data loss depending on the frequency of database and file backups. |
| **Limited Outage**<br />Downtime Tolerance: one week or more | To recover from this outage, a periodic backup must be taken of each database repository and certain DbProtect application files. This approach does not require additional standby hardware and can be built on the same or replacement hardware. |

### Bulk Data Management

Results of scan jobs, audits and pen tests, can be exported, imported, and purged from the system. This feature allows exporting scan job results older than a specified cutoff date and, optionally, purging them.

When needed, these results can be imported back into DbProtect and will then be available for reporting.

Located in the `EnterpriseServicesHost\util` folder under the product installation directory, three new command line utilities provide these features:

* `ExportResults.bat`
* `ImportResults.bat`
* `PurgeResults.bat`

These utilities will prompt for DbProtect user credentials. The supplied user credentials must have the DbProtect System Administrator role.

Using the Windows command prompt, run any of these commands with no arguments to receive detailed usage information.

## Appendix E: Asset Import Example CSV Information

At times it is easier to import assets, compared to manual creation, when there are a large number of records. This information is also contained in the DbProtect **Assets** page when you click **Import** and then the hyperlink for "View Sample File" on the top right.

This is a sample asset import file for DbProtect 6.5 and later. It is recommended to test your import file content before you run an import by clicking the **Test Import** button in the **Import** dialog. Asset imports require the following columns:

* host
* port
* instanceName
* assetType

The following is an import which contains a sampling of assets of different types and only the required columns:

```csv theme={null}
host,port,instanceName,assetType
oracle11gdev,1521,ORCL,Oracle
172.16.32.133,5000,PREPROD,Sybase
172.16.32.57,49396,DOCS,Microsoft SQL Server
172.16.32.79,5000,RHL64SYBASE15,Sybase
172.16.32.87,1521,ORCLWS,Oracle
172.16.32.97,1433,MSSQLSERVER,Microsoft SQL Server
172.16.33.1,3701,db2inst1,IBM DB2
```

The following is an import which contains a sampling of assets of different types and optional asset fields:

```csv theme={null}
host,port,instanceName,assetType,assetVersion,platform
oracle11gdev,1521,ORCL,Oracle,Oracle11gR2 Database,Microsoft Windows
172.16.32.133,5000,PREPROD,Sybase,Sybase 12.5 Database,Linux
172.16.32.57,49396,DOCS,Microsoft SQL Server,Microsoft SQL Server 2008 R2,Microsoft Windows
172.16.32.79,5000,RHL64SYBASE15,Sybase,Sybase 15.0 Database,Unknown Platform
172.16.32.87,1521,ORCLWS,Oracle,Oracle11gR2 Database,Solaris
172.16.32.97,1433,MSSQLSERVER,Microsoft SQL Server,Microsoft SQL Server 2008,Microsoft Windows
172.16.33.1,3701,db2inst1,IBM DB2,DB2 Database,Linux
```

Users can also import assets and their attributes at the same time. The following is an example of an asset import with custom attributes "Primary Application", "Organization", and "Owner":

```csv theme={null}
host,port,instanceName,Primary Application,assetType,assetVersion,platform,Organization,Owner
oracle11gdev,1521,ORCL,Oracle Dev Box NYC,Oracle,Oracle11gR2 Database,Microsoft Windows,America,John Doe
172.16.32.133,5000,PREPROD,Pre Production Staging Syb 12.5,Sybase,Sybase 12.5 Database,Linux,China,Jane Doe
172.16.32.57,49396,DOCS,Documentation Repository,Microsoft SQL Server,Microsoft SQL Server 2008 R2,Microsoft Windows,,
172.16.32.79,5000,RHL64SYBASE15,,Sybase,Sybase 15.0 Database,Unknown Platform,Latin America,none
172.16.32.87,1521,ORCLWS,Web Server,Oracle,Oracle11gR2 Database,Solaris,Europe,John Doe
172.16.32.97,1433,MSSQLSERVER,,Microsoft SQL Server,Microsoft SQL Server 2008,Microsoft Windows,Europe,
172.16.33.1,3701,db2inst1,,IBM DB2,DB2 Database,Linux,America, John Doe
```

System attributes are attributes that are reserved by DbProtect. More information on reserved system attributes can be found in the *Pre-defined Attributes* table in [Use search expressions](#use-search-expressions).

* **pipeName**: overrides the default pipe name for Microsoft SQL Server connections. This credential type should specify 'Named Pipe' as the network protocol.
* **oracleServiceName**: specifies a service name to be used for connecting to an Oracle asset.
* **scanGroup**: specifies a scan group for this asset. Only scanners belonging to the specified scan group will be used for scanning this asset. This only applies if scan groups have been configured under **Set Up** | **System Settings** | **Scan Engines**.
* **assetGroup**: Specifies a group for this asset.

Import Example:

```csv theme={null}
host,port,instanceName,assetType,assetVersion,platform,pipeName,oracleServiceName,scanGroup,assetGroup
oracle11gdev,1521,ORCL,Oracle,Oracle11gR2 Database,Microsoft Windows,,oracle11gservicename,Oracle Group,Oracle 11G Asset Group
172.16.32.133,5000,PREPROD,Sybase,Sybase 12.5 Database,Linux,,,Sybase Scan Group, Sybase Asset Group
172.16.32.57,49396,DOCS,Microsoft SQL Server,Microsoft SQL Server 2008 R2,Microsoft Windows,docspipename,,SQL Server, SQLServer Asset Group
172.16.32.79,5000,RHL64SYBASE15,Sybase,Sybase 15.0 Database,Unknown Platform,,,Sybase Scan Group, Sybase Asset Group
172.16.32.87,1521,ORCLWS,Oracle,Oracle11gR2 Database,Solaris,,orclwsservicename,Oracle Group,Oracle 11G Asset Group
172.16.32.97,1433,MSSQLSERVER,Microsoft SQL Server,Microsoft SQL Server 2008,Microsoft Windows,,,SQL Server, SQLServer Asset Group
172.16.33.1,3701,db2inst1,IBM DB2,DB2 Database,Linux,,,IBM DB2, DB2 Asset Group
```

For the following columns, the noted fields in the DbProtect Asset Detail pane (when creating or editing an asset) are used and contain the valid values to be used in the import file.

| CSV value | GUI Value |
| - | - |
| assetType | Type |
| assetVersion | Version |
| platform | Platform |

## Appendix F: Report Mapping

| Explorer Job | Explorer Location |
| - | - |
| | Explorer \| Security Overview \| Alerts \| Click to Drill-in \| Select time frame |
| | Entitlement Exploration \| Users \| User \| Select User |
| | Entitlement Exploration \| Users \| Roles \| Select Role |
| | Entitlement Exploration \| Users \| User \| Select User |
| | Entitlement Exploration \| Objects |
| | Entitlement Exploration \| Objects (Select Org at top right) |
| | Entitlement Exploration \| Users \| Roles \| Select Role \| Select Asset drop-down |
| | Entitlement Exploration \| Users \| Roles (Select Org at top right) Security Overview \| Exploitable Privileged Users |
| | Entitlement Exploration \| Users \| Users \| Select Asset drop-down |
| | Entitlement Exploration \| Users \| Users (Select Org at top right) |
| | Explorer \| Dashboard \| Security Overview \| Assets Explorer \| Dashboard \| Security Overview \| Assets \| Click to Drill-in \| Select Asset Types |
| | Explorer \| Dashboard \| Security Overview \| Assets \| Click to Drill-in \| Select Asset Types |
| | Explorer \| Dashboard \| Security Overview \| Assets \| Click to Drill-in \| Select Asset Types |
| | Explorer \| Dashboard \| Security Overview \| Assets |
| Check Results Details | |
| Check Results Summary | |
| Check Status | |
| CIS Compatible Results Details | |
| CIS Compatible Results Summary | |
| DISA STIG Findings Detail | Explorer \| Frameworks |
| DISA STIG Findings Summary | Explorer \| Frameworks |
| DISA STIG Overall Status | Explorer \| Frameworks |
| | Explorer \| Dashboard \| Security Overview |
| | Explorer \| Dashboard \| Vulnerabilities |
| Findings Detail | Explorer \| Dashboard \| Vulnerabilities |
| Findings Distribution | Explorer \| Risk Overview |
| Findings Overview | Explorer \| Dashboard \| Vulnerabilities |
| Findings Summary | Explorer \| Dashboard \| Vulnerabilities |
| | Explorer \| Dashboard \| Vulnerabilities |
| | Explorer \| Dashboard \| Vulnerabilities |
| | Explorer \| Dashboard \| Vulnerabilities |
| | Explorer \| Dashboard \| Vulnerabilities |
| | Explorer \| Dashboard \| Risk Overview \| Organizational Risk – All Findings |
| Job Errors | |
| Job Status | |
| Knowledgebase Detail | Explorer \| Policies |
| Latest Activity Details | Explorer \| Alerts |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Entitlements Exploration |
| | Explorer \| Dashboard \| Risk Overview \| Organizational Risk – All Findings |
| | Explorer \| Dashboard \| Risk Overview \| Organizational Risk – All Findings |
| | Explorer \| Entitlements Exploration |
