Rules on flat

The rules on flat setting changes the way Guardium processes policy rules.

When Rules on flat is checked:
  • Session-Level rules will be examined in real-time.
  • No rules will be evaluated when the offline processing does takes place.
When Rules on flat is NOT checked:
  • Policy rules will fire at processing time using the current installed policy.
Note: Rules on flat does not work with policy rules involving a field, an object, SQL verb (command), Object/Command Group, and Object/Field Group. In the Flat Log process, "flat" means that a syntax tree is not built. If there is no syntax tree, then the fields, objects and SQL verbs cannot be determined.

The following actions do not work with rules on flat policies: LOG_FULL_DETAILS; LOG_FULL_DETAILS_PER_SESSION; LOG_FULL_DETAILS_VALUES; LOG_FULL_DETAILS_VALUES_PER_SESSION; LOG_MASKED_DETAILS.