QRadar: Microsoft SQL Server account privileges are required for logging events in QRadar

What permissions do we need on a Microsoft SQL Server to allow QRadar to query the AuditData table?


Insufficient privileges granted to the SQL user account will cause QRadar to be unable to collect events from Microsoft SQL Server.


Before you begin: This configuration is for Microsoft SQL Server 2008 - 2012. Check your SQL Server documentation for other revisions.

The Microsoft SQL Server Log Source requires a user with the SELECT privilege on dbo.AuditData view. Per our DSM Guide, the dbo.AuditData view is created based on the sys.fn_get_audit_file function, which requires CONTROL SERVER permissions.

The fact that the user in question cannot query the view might be due to insufficient permissions granted.

For more information please reference the, Microsoft Library - sys.fn_get_audit_file .

03 April 2020