IBM Support

Guardium FullSQL report shows succeeded=1 even when the SQL failed

Troubleshooting


Problem

The IBM Security Guardium sniffer does not record the success or failure of SQL in the Full SQL domain unless inspection engines are configured to 'inspect returned data'. Reports always show the default value, "Succeeded = 1" for the Full SQL/Succeeded entity.
This behavior is working as designed.

Symptom

For example, run SQL that triggers an 'insufficient privileges' error so the SQL execution fails.
Guardium logs the SQL to the Full SQL domain because the SQL matched a policy rule set to Log Full Details. Reports show Succeeded=1 for that SQL even though it failed.

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Component":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"v10.6","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
11 March 2020

UID

ibm15695659