Chat now with support
Chat with Support

Change Auditor for SQL Server 7.2 - Event Reference Guide

SQL Security Audit Event

The SQL Security Audit Event facility contains security audit events.

Audit Access Database Object

Created when the object is accessed.

Medium

Audit Add DB User

Created when the identified login is added as a database user.

Medium

Audit Add Login

Created when the identified SQL Server login is added to the server.

Medium

Audit Add Login to Server Role

Created when the identified login is added to the fixed server role.

Medium

Audit Add Member to DB Role

Created when the identified login is added to the database role.

Medium

Audit Add Role

Created when the database role is added to the database.

Medium

Audit Administer Bulk Server Operations

Created when a bulk server operation is administered.

Medium

Audit Alter Database

Created when the database is altered.

Medium

Audit Alter Database Object

Created when the object is altered.

Medium

Audit Alter Database Principal

Created when the Database Principle is altered.

Medium

Audit Alter Object Derived Permission

Created when an object with derived permissions is altered.

Medium

Audit Alter Schema Object

Created when a schema object is altered.

Medium

Audit Alter Server Object

Created when a server object is altered.

Medium

Audit Alter Server Principal

Created when a server principal object is altered.

Medium

Audit Alter Server Resources

Created when a server resource is altered.

Medium

Audit Alter Server Settings

Created when a server setting is altered.

Medium

Audit Alter Server State Operations

Created when a server state operation is altered.

Medium

Audit App Role Change Password

Created when a password is changed for the application role.

Medium

Audit Authenticate Server Operations

Created when an authenticate server operation is used.

Medium

Audit Backup

Created when a backup command is issued.

Medium

Audit Backuplog

Created when a backuplog command is issued.

Medium

Audit Broker Conversation - Invalid Signature

Created when the Service Broker could not verify the message signature supplied by the sender using the public key in the sender's certificate.

Medium

Audit Broker Conversation - No Certificate

Created when the Service Broker could not locate a usable certificate for one of the participants in the conversation.

Medium

Audit Broker Conversation - No Security Header

Created during a secure conversation when the Service Broker received a message that did not contain a session key.

Medium

Audit Broker Conversation - Run as Target Failure

Created when the destination user does not have receive permissions on the destination queue.

Medium

Audit Broker Login - Authentication Failure

Created when an Authentication Failure event reports that the Service Broker cannot perform authentication for the connection due to an error.

Medium

Audit Broker Login - Authorization Failure

Created when an Authorization Failure event reports that the Service Broker denied authorization for the connection.

Medium

Audit Broker Login - Login Protocol Error

Created when a Login Protocol Error event reports that the broker received a message that is well-formed but not valid for the current state of the login process.

Medium

Audit Broker Login - Login Success

Created when a Login Success event reports that the adjacent broker login process has finished successfully.

Medium

Audit Broker Login - Message Format Error

Created when a Message Format Error event reports that the broker received a message that does not match the expected format.

Medium

Audit Broker Login - Negotiate Failure

Created when a Negotiate Failure event reports that the local broker and the remote broker support mutually exclusive levels of authentication.

Medium

Audit Change Audit - Audit Started

Created when an audit trace is started. (Disabled by default)

Medium

Audit Change Audit - Audit Stopped

Created when an audit trace is stopped. (Disabled by default)

Medium

Audit Change Audit - C2 Mode OFF

Created when the C2 audit mode is turned OFF.

Medium

Audit Change Audit - C2 Mode ON

Created when the C2 audit mode is turned ON.

Medium

Audit Change Database Owner

Created when the ALTER AUTHORIZATION statement is used to change the owner of the database and the permissions required to do that are checked.

Medium

Audit Change Member in DB Role

Created when the database role has changed for the identified database login.

Medium

Audit Create Database

Created when the database is created.

Medium

Audit Create Database Object

Created when the object is created.

Medium

Audit Create Database Principal

Created when the Database Principle is created.

Medium

Audit Create Object with Derived Permission

Created when an object with derived permissions is created. (Disabled by default)

Medium

Audit Create Schema Object

Created when a schema object is created.

Medium

Audit Create Server Object

Created when a server object is created.

Medium

Audit Create Server Principal

Created when a server principal object is created.

Medium

Audit Database Mirroring Login - Authentication Failure

Created when an Authentication Failure event reports that a database mirroring endpoint cannot perform authentication for the connection due to an error.

Medium

Audit Database Mirroring Login - Authorization Failure

Created when an Authorization Failure event reports that a database mirroring endpoint denied authorization for the connection.

Medium

Audit Database Mirroring Login - Login Protocol Error

Created when a Login Protocol Error event reports that the database mirroring login receives a message that is well-formed but not valid for the current state of the login process.

Medium

Audit Database Mirroring Login - Login Success

Created when a Login Success event reports that the adjacent database mirroring login process has finished successfully.

Medium

Audit Database Mirroring Login - Message Format Error

Created when a Message Format Error event reports that the database mirroring login received a message that does not match the expected format.

Medium

Audit Database Mirroring Login - Negotiate Failure

Created when a Negotiate Failure event reports that the local database mirroring endpoint and the remote database mirroring endpoint support mutually exclusive levels of authentication.

Medium

Audit Database Object Access

Created when the database object is accessed with the identified permissions.

Medium

Audit Database Object GDR - Deny

Created when the permissions are denied.

Medium

Audit Database Object GDR - Grant

Created when the permissions are granted.

Medium

Audit Database Object GDR - Revoke

Created when the permissions are revoked.

Medium

Audit Database Object Take Ownership

Created when the object is assigned the new owner.

Medium

Audit Database Operation – Checkpoint

Created when the checkpoint operation occurred in the database.

Medium

Audit Database Operation - Subscribe to Query Notification

Created when subscription to query notification occurred in the database.

Medium

Audit Database Principal Impersonation

Created when an impersonation occurred within the database scope with the identified permissions.

Medium

Audit Database Scope GDR - Deny

Created when a DENY is issued for permissions for database-only actions.

Medium

Audit Database Scope GDR - Grant

Created when a GRANT is issued for permissions for database-only actions.

Medium

Audit Database Scope GDR - Revoke

Created when a REVOKE is issued for permissions for database-only actions.

Medium

Audit DBCC

Created when a DBCC command is issued.

Medium

Audit Disable Server Principal

Created when a server principal object is disabled.

Medium

Audit Drop Credential Mapping

Created when a credential mapping is dropped for the login.

Medium

Audit Drop Database

Created when the database is dropped.

Medium

Audit Drop Database Object

Created when the object is dropped.

Medium

Audit Drop Database Principal

Created when the Database Principle is dropped.

Medium

Audit Drop DB User

Created when the identified login is dropped as a database user.

Medium

Audit Drop Login

Created when the identified SQL Server login is removed from the server.

Medium

Audit Drop Login from Server Role

Created when the identified login is removed from the fixed server role.

Medium

Audit Drop Member from DB Role

Created when the identified login is removed from the database role.

Medium

Audit Drop Object with Derived Permission

Created when an object with derived permissions is dropped. (Disabled by default)

Medium

Audit Drop Role

Created when the database role is removed from the database.

Medium

Audit Drop Schema Object

Created when a schema object is dropped.

Medium

Audit Drop Server Object

Created when a server object is dropped.

Medium

Audit Drop Server Principal

Created when a server principal object is dropped.

Medium

Audit Dump Database

Created when the database is dumped.

Medium

Audit Dump Database Object

Created when the object is dumped.

Medium

Audit Dump Database Principal

Created when the Database Principle is dumped.

Medium

Audit Dump Object Derived Permission

Created when an object with derived permissions is dumped.

Medium

Audit Dump Schema Object

Created when a schema object is dumped.

Medium

Audit Dump Server Object

Created when a server object is dumped.

Medium

Audit Dump Server Principal

Created when a server principal object is dumped.

Medium

Audit Enable Server Principal

Created when a server principal object is enabled.

Medium

Audit External Access Server Operations

Created when an external access server operation is used.

Medium

Audit Grant Database Access to DB User

Created when the identified login is granted access to the database.

Medium

Audit Load Database Object

Created when the object is loaded.

Medium

Audit Load Database Principal

Created when the Database Principle is loaded.

Medium

Audit Load Object Derived Permission

Created when an object with derived permissions is loaded.

Medium

Audit Load Schema Object

Created when a schema object is loaded.

Medium

Audit Load Server Object

Created when a server object is loaded.

Medium

Audit Load Server Principal

Created when a server principal object is loaded.

Medium

Audit Login

Created when the user has successfully logged in to the SQL Server.

Medium

Audit Login Change Credential Property

Created when the credential property of the login has changed.

Medium

Audit Login Change Default Database Property

Created when the default database property of the login has changed.

Medium

Audit Login Change Default Language Property

Created when the default language property of the login has changed.

Medium

Audit Login Change Expiration Property

Created when the expiration property of the login has changed.

Medium

Audit Login Change Name Property

Created when the name property of the login has changed.

Medium

Audit Login Change Policy Property

Created when the policy property of the login has changed.

Medium

Audit Login Change Password - Changed

Created when the SQL Server login password is changed for the user.

Medium

Audit Login Change Password - Must Change

Created when the SQL Server login password must change for the user.

Medium

Audit Login Change Password - Reset

Created when the SQL Server login password is reset for the user.

Medium

Audit Login Change Password - Self Changed

Created when the SQL Server login password is self changed for the user.

Medium

Audit Login Change Password - Self Reset

Created when the SQL Server login password is self reset for the user.

Medium

Audit Login Change Password – Unlocked

Created when the SQL Server login password has been unlocked for the user.

Medium

Audit Login Change Policy Property

Created when the policy property of the login has changed.

Medium

Audit Login Failed

Created when the user tried to log in to the SQL Server and failed.

Medium

Audit Login GDR - Deny

Created when a Windows Login right is denied for the login.

Medium

Audit Login GDR - Grant

Created when a Windows Login right is granted for the login.

Medium

Audit Login GDR - Revoke

Created when a Windows Login right is revoked for the login.

Medium

Audit Logout

Created when the user has logged out of the SQL Server.

Medium

Audit Map Credential Login

Created when a credential is mapped to the login.

Medium

Audit Open Database Object

Created when the object is opened.

Medium

Audit Restore

Created when a restore command is issued.

Medium

Audit Revoke Database Access from DB User

Created when the identified login is revoked access to the database.

Medium

Audit Schema Object Access

Created when a schema object is used with permissions. (Disabled by default)

Medium

Audit Schema Object GDR - Deny

Created when permissions are denied for a schema object.

Medium

Audit Schema Object GDR - Grant

Created when permissions are granted to a schema object.

Medium

Audit Schema Object GDR - Revoke

Created when permissions are revoked from a schema object.

Medium

Audit Schema Object Take Ownership

Created when a schema object is assigned a new owner.

Medium

Audit Server Alter Trace

Created when a trace is altered. (Disabled by default)

Medium

Audit Server Object GDR - Deny

Created when permissions are denied for a server object.

Medium

Audit Server Object GDR - Grant

Created when permissions are granted to a server object.

Medium

Audit Server Object GDR - Revoke

Created when permissions are revoked from a server object.

Medium

Audit Server Object Take Ownership

Created when a server object is assigned to a new owner.

Medium

Audit Server Pause

Created when the SQL Server service is paused.

Medium

Audit Server Principal Impersonation

Created when an impersonation occurred within the server scope.

Medium

Audit Server Resume

Created when the SQL Server service is resumed.

Medium

Audit Server Scope GDR - Deny

Created when a DENY is issued for permissions in the server scope.

Medium

Audit Server Scope GDR - Grant

Created when a GRANT is issued for permissions in the server scope.

Medium

Audit Server Scope GDR - Revoke

Created when a REVOKE is issued for permissions in the server scope.

Medium

Audit Server Shutdown

Created when the SQL Server service is shutdown.

Medium

Audit Server Start

Created when the SQL Server service is started.

Medium

Audit Statement Permission

Created when statement permissions are used.

Medium

Audit Transfer Schema Object

Created when a schema object is transferred.

Medium

SQL Server Event

The SQL Server Event facility contains general server events.

Mount Tape Cancel

Created when a tape mount request is canceled.

Medium

Mount Tape Complete

Created when a tape mount request is completed.

Medium

Mount Tape Request

Created when a tape mount request is received.

Medium

Server Memory Decrease

Created when the memory usage is decreased for the SQL Server.

Medium

Server Memory Increase

Created when the memory usage is increased for the SQL Server.

Medium

Trace File Close

Created when a trace file has been closed during rollback.

Medium

SQL Session Event

The SQL Session Event facility contains general session events.

Plan Guide Successful

Created when the SQL Server successfully produces an execution plan for a query or batch that contained a plan guide.

Medium

Plan Guide Unsuccessful

Create when the SQL Server can not produce an execution plan for a query or batch that contained a plan guide.

Medium

PreConnect:Completed

Created when a LOGON trigger or the Resource Governor classifier function has finished execution

Medium

PreConnect:Starting

Created when a LOGON trigger or the Resource Governor classifier function started execution

Medium

SQL Stored Procedures Event

The SQL Stored Procedures Event facility contains general stored procedure events.

RPC Output Parameter

Created when the output parameter values of a remote procedure call is available.

Medium

RPC:Completed

Created when a remote procedure call has been completed. (Disabled by default)

Medium

RPC:Starting

Created when a remote procedure call has started. (Disabled by default)

Medium

SP:CacheHit – Compplan Hit

Created when a complied plan was found in the plan cache. (Disabled by default)

Medium

Sp:CacheHit – Execution Context Hit

Created when a free execution plan was found in the plan cache. (Disabled by default)

Medium

SP:CacheInsert

Created when a stored procedure has been inserted into the procedure cache.

Medium

SP:CacheMiss

Created when a stored procedure is not found in the cache. (Disabled by default)

Medium

SP:CacheRemove - Compplan Remove

Created when a compiled query plan has been removed from the cache.

Medium

SP:CacheRemove – Proc Cache Flush

Created when all entries have been removed from the procedure cache.

Medium

SP:Completed

Created when a stored procedure has completed executing. (Disabled by default)

Medium

SP:Recompile – Browse Perms Changed

Created when a stored procedure has been recompiled for browse perms changes.

Medium

SP:Recompile – Cursor Options Changed

Created when a stored procedure has been recompiled for cursor options changes.

Medium

SP:Recompile – MPI View Changed

Created when a stored procedure has been recompiled for MPI view changes.

Medium

SP:Recompile – Query Notification Environment Changed

Created when a stored procedure has been recompiled for query notification environment changes.

Medium

SP:Recompile – Recompile DNR

Created when a stored procedure has been recompiled for DNR recompiles. (Disabled by default)

Medium

SP:Recompile – Recompile Option

Created when a stored procedure has been recompiled with recompile option.

Medium

SP:Recompile – Remote Rowset Changed

Created when a stored procedure has been recompiled for remote rowset changes.

Medium

SP:Recompile – Schema Changed

Created when a stored procedure has been recompiled for schema changes.

Medium

SP:Recompile – Set Option Changed

Created when a stored procedure has been recompiled for set option changes. (Disabled by default)

Medium

SP:Recompile – Statistics Changed

Created when a stored procedure has been recompiled for statistics changes. (Disabled by default)

Medium

SP:Recompile – Temp Table Changed

Created when a stored procedure has been recompiled for temp table changes.

Medium

SP:Starting

Created when a stored procedure is beginning execution. (Disabled by default)

Medium

SP:StmtCompleted

Created when a Transact-SQL statement within a stored procedure has completed. (Disabled by default)

Medium

SP:StmtStarting

Created when a Transact-SQL statement within a stored procedure has started. (Disabled by default)

Medium

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating