Core component of SQL Server for storing, processing, and securing data
Thanks, @Anonymous for the follow-up.
Due to time constraints, we created XE events for specific accounts on each server. However, I tried your suggestion (mentioned in Part 1) by modifying the script, and it works fine on the test servers. I will monitor these events for a few weeks, and if they provide the required output, we will implement them on the production servers as well. Thanks again for your suggestions.
CREATE EVENT SESSION Audit_Sysadmin_Logins_test
ON SERVER
ADD EVENT sqlserver.login
(
ACTION
(
sqlserver.client_app_name,
sqlserver.username,
sqlserver.client_hostname,
sqlserver.server_principal_name,
sqlserver.session_id
)
WHERE
(
-- Exclude DBA / service accounts
[server_principal_name] <> 'DOMAIN\dba_user1'
AND [server_principal_name] <> 'dba_user2'
AND [server_principal_name] <> 'DOMAIN\dba_use3'
AND [server_principal_name] <> 'dba_user4'
)
)
ADD TARGET package0.event_file
(
SET
filename = N'R:\Extended_Events\Audit_Sysadmin_Logins.xel',
max_file_size = 50,
max_rollover_files = 5
);
GO