DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Part ofRuntime Visibility

Database Activity Monitoring

Audit-Ready Evidence

Record database sessions and operations as searchable trails, alerts, and reports for investigations and audit.

  • Capture Activity
  • Add Context
  • Investigate and Report

Capture activity, add context, and build audit evidence

Database Activity Monitoring records who used a database, what they did, and what happened next. It gives security, database, and compliance teams searchable evidence for investigations, privileged-user oversight, alerts, and reporting.

DataSunrise can monitor activity through a database proxy, passive network monitoring, a host agent, or database audit records. Teams can use one method or combine them to cover network, local, and managed database activity in one investigation workflow.

See the workflow in DataSunrise

Product screens show how policy, evidence, and protection appear in practice.

Choose How to Capture Database Activity

  • DataSunrise proxy

    Monitor + protect

    Use it when you need monitoring together with live firewall or dynamic masking.

    What changes
    Applications connect to the database through DataSunrise.
    Operational impact
    Adds a network hop. Plan high availability for maintenance and uptime.
  • Passive sniffer

    Monitor

    Use it when applications should keep connecting directly to the database.

    What changes
    A copy of network traffic is sent to DataSunrise.
    Operational impact
    Runs outside the live request path. Traffic mirroring is required; encrypted or local sessions may need another method.
  • Host agent

    Database-specific

    Use it when supported local or loopback database activity must be included.

    What changes
    An agent is installed on a supported database host.
    Operational impact
    Uses database-host resources. Protection, installation, and restart requirements vary by database and release.
  • Native audit

    Monitor

    Use it when the database or managed service already produces useful audit records.

    What changes
    Native auditing is enabled and its records are connected to DataSunrise.
    Operational impact
    Uses database-side logging and storage. The impact depends on the audit scope and database configuration.

Availability varies by database, version, and deployment. The database monitoring matrix shows the currently documented paths.

Explore Database Activity Monitoring

1 / 3

Focus on the Activity That Matters

Audit rules select the database events that need attention. Teams can watch privileged users, sensitive objects, schema changes, failed access, bulk exports, query types, session events, and SQL injection indicators.

A rule can save the event, trigger an alert, or add it to a report for an investigation, recurring security review, or compliance check.

Data Audit Workflow

Data Audit turns selected monitoring records into evidence teams can search, review, and include in reports. Transactional Trails bring related sessions and events into one view. Alerts flag activity that needs attention.

Teams can filter activity by user, application, client, database object, operation, outcome, and time to reconstruct an incident.

The workflow supports privileged-user oversight, incident investigation, change review, recurring security reviews, and audit preparation.

Monitor Databases Across Modern Environments

DataSunrise monitors databases on premises, in virtual machines, and in managed cloud services. Examples include Oracle, PostgreSQL, Microsoft SQL Server, MySQL and MariaDB, Amazon RDS and Aurora, Redshift, DocumentDB, Google BigQuery, Snowflake, Databricks, and Qdrant.

The integration directory shows the collection and protection options available for the database in your environment.

FAQ

Frequently Asked Questions

Is Data Audit a separate product?

No. Data Audit is the investigation and evidence workflow within Database Activity Monitoring.

Do I need a proxy to monitor database activity?

No. DataSunrise can also collect activity through passive sniffing, host agents, and database audit records. The proxy adds the ability to block requests or mask live results.

Can DataSunrise identify the user behind a shared database account?

Yes, when the application passes the user identity to DataSunrise. Application-User Attribution links that person to activity recorded under the shared account.

How long is audit evidence kept?

The retention period and storage protection settings are configured for each deployment.

See how DataSunrise works with your technology stack

View Integration Examples