I enable auditing for ase and then check information for sysaudits_xx table like:
select * from sysaudits_02 order by eventtime desc
and got same data like:
event | eventmod | spid | eventtime | sequence | suid | dbid | objid | xactid | loginname | dbname | objname | objowner | extrainfo | ||
16 | 45 | 1 | 130 | 05/15/2014 1:49:03.353 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
17 | 45 | 1 | 170 | 05/15/2014 1:49:03.320 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
18 | 45 | 1 | 84 | 05/15/2014 1:49:03.283 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
19 | 45 | 1 | 82 | 05/15/2014 1:49:03.243 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
20 | 45 | 1 | 141 | 05/15/2014 1:49:03.210 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
21 | 45 | 1 | 80 | 05/15/2014 1:49:03.170 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
22 | 45 | 1 | 71 | 05/15/2014 1:49:03.133 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
23 | 45 | 1 | 52 | 05/15/2014 1:49:03.096 PM | 1 | 38 | 5 | [NULL] | [NULL] | mylogin | mydb | [NULL] | [NULL] | ; ; ; ; myhost, 192.168.1.17; ; mylogin/ase; | |
what kind of event monitored for with this data? how to stop monitoring on this event?
Also how to check all auditing setting is on. For example, if I turn on audit on disk like:
sp_audit "disk", "all", "all", "on"
then how to know how many auditing event is on in the future(maybe set by someone else)?