IBM Support

IBM Security Guardium: The only object associated with the MongoDB command db.grantRolesToUser is the user and the collection is not logged.

Question & Answer


Question

If I execute the command db.grantRolesToUser on a MongoDB collection the only object associated with that command is the user. The collection that the role was granted on is not logged in the Guardium report as an object. For example: db.grantRolesToUser( "testUser", ["readWrite", {role: "read",db:"Collection1"} Using the above example the verb logged is "grantRolesToUser" and the object stored in the Guardium report is the user name "testUser". Is this expected behaviour, and why does this behaviour not match other databases?

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"Guardium Appliances","Platform":[{"code":"PF016","label":"Linux"}],"Version":"10.1;10.1.2;10.1.3;10.1.4;10.5","Edition":"All Editions","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
22 June 2018

UID

swg22016837