IBM Support

Release of Guardium Data Protection sniffer patch 12.0p4016

Release Notes


Abstract

This technical note provides guidance for installing IBM Guardium Data Protection sniffer patch 12.0p4016, including any new features or enhancements, resolved or known issues, or notices associated with the patch.

Content

Patch information
  • Patch file name: SqlGuard-12.0p4016_Snif_Mar_14_2026.tgz.enc.sig
  • MD5 checksum:  971b01806efaf3c1fa760beb484225ef
 
Finding the patch 
  1. Select the following options to download this patch on the IBM Fix Central website and click Continue.
    1. Product selector: IBM Security Guardium
    2. Installed Version: 12.0, 12.1, or 12.2
    3. Platform: All
  2. On the "Identify fixes" page, select Browse for fixes and click Continue.
  3. On the "Select fixes" page, select Appliance Sniffer Patch. Then, enter the patch information in the Filter fix details field to locate the patch.
 
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
 
 
Installation
Notes:
  • This universal sniffer patch can be installed on releases of Guardium 12.0, 12.1, and 12.2.
  • Sniffer patches are cumulative, they contain all previous sniffer patches for that major version.
  • This patch restarts the sniffer process.
 
Overview:
  1. Download the patch and extract the compressed package outside the Guardium system.
  2. Be sure to check the latest version of these patch release notes online just before you install this patch.
  3. Pick a "quiet" or low-traffic time  to install the patch on the Guardium system.
  4. Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.  This sniffer patch must be installed across all the appliances such as the central manager, aggregators, and collectors.
 
For more information, see How to install patches in the Guardium documentation.
 
 
New currency items
This patch provides the following new currency items.
 
  • Amazon Aurora MySQL 8.0.mysql_aurora.3.10.3
  • Cloudera 7.3.1
  • Elasticsearch compression (support for compressed traffic monitoring)
  • Greenplum 7.5.2 (UNIX only)
  • Microsoft SQL Server 2025
  • Milvus 2.6.7
  • Neo4j 2025.10.1
  • OpenSearch 3.4.0
  • Oracle AI Database 26ai 
 
 
Resolved issues
This patch resolves the following issues.
 
PatchIssue keySummaryKnown issue (APAR)
12.0p4015 See release notes for sniffer patch 12.0p4015. 
12.0p4016GRD-111999Fixed Windows Software TAP (S-TAP) Protocol 8 heart beat message handling.DT454959
 GRD-112938Original SQL values masking improvements.DT464193
 GRD-114362Added corner case handling for failed login logging for Azure Event Hub.DT464171
 GRD-115522Fixed IBM Db2 error processing.DT464192
 GRD-115917Fixed sniffer instability for OceanBase.DT464986
 GRD-117294Successful DB SQL commands sometimes had the %%LastError field set with a parser error message. Now, If the parser error is due to SQL truncation, Guardium marks the parser error with "GRD" and TRUNCATED” in the %%LastError field.DT464191
 GRD-117584Improved session-level policy SQL criteria processing.DT464249
 GRD-117890Fixed Microsoft SQL parser issues.DT463744
 GRD-118849Fixed IBM Db2 parser errors. 
 GRD-119269Fixed connection issue between datastreams and sniffer.DT462924
 GRD-121280Fixed PostgreSQL parser errors.DT465468
 GRD-121534For A-TAP enabled environment, eliminate collector side session info correlation, if it was correlated on the S-TAP side. 
 
 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"},{"code":"a8m0z000000Gp0SAAS","label":"SNIFFER"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.0.0;12.1.0;12.2.0"}]

Document Information

Modified date:
31 March 2026

UID

ibm17267761