Which two (2) requirements must a query satisfy to be available for use by a correlation alert?
IBM Guardium makes a query available for a correlation alert only when it includes at least one date (timestamp) field and a Count field; user access is also required. Logging full query results is optional, and neither a Client/Server By Session main entity nor exclusive execution on Aggregators is required.
Community Discussion