Click here to monitor SSC
SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 
        
Home       Members    Calendar    Who's On


Add to briefcase 12»»

SQL Server 2005 Logon Triggers Expand / Collapse
Author
Message
Posted Thursday, April 06, 2006 1:12 PM
SSC-Enthusiastic

SSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-Enthusiastic

Group: General Forum Members
Last Login: Tuesday, April 19, 2011 1:27 AM
Points: 116, Visits: 59
Comments posted to this topic are about the content posted at http://www.sqlservercentral.com/columnists/FVandeputte/sqlserver2005logontriggers.asp
Post #271709
Posted Monday, April 17, 2006 8:56 AM
Hall of Fame

Hall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of Fame

Group: General Forum Members
Last Login: Thursday, December 26, 2013 9:45 AM
Points: 3,475, Visits: 577

This is a good article!

Question: the stored procedure LogginProc is doing the endless loop waiting for the logon event description to be queued and when it finds one it pulls the information from the queue. Is it really a trigger? I can do the similar thing with the traces. You just set up a server-side trace with logging to the trace file. Than the logon events will be logged to the trace file. Then you can select from the trace file into any table or you may select to keep this info in the trace file because you can query it too by fn_trace_gettable. I do understand that we will have to wait until trace file rolls over to get the information but it will be logged anyway.

But in general, this article is a very good and easy to understand example on how to use the Service Broker.

 

 




Regards,
Yelena Varshal

Post #273558
Posted Tuesday, April 18, 2006 11:24 AM
SSC-Enthusiastic

SSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-Enthusiastic

Group: General Forum Members
Last Login: Tuesday, April 19, 2011 1:27 AM
Points: 116, Visits: 59
Yelena,

You are right, you can get the same results by running a trace and saving it to a table. However I think event notifications are more robust and more flexible.

I named the article SQL Server Logon triggers, refering to Oracle. But on SQL Server they are not really triggers.

Kind regards,

Frederik
Post #273729
Posted Wednesday, July 26, 2006 12:22 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: General Forum Members
Last Login: Wednesday, January 17, 2007 9:44 AM
Points: 2, Visits: 1
but how to you disable unwanted logon like determine who from which workstation using which program. service broker will not kill the other one right?
Post #297563
Posted Tuesday, November 14, 2006 7:00 AM
SSC-Enthusiastic

SSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-EnthusiasticSSC-Enthusiastic

Group: General Forum Members
Last Login: Tuesday, April 19, 2011 1:27 AM
Points: 116, Visits: 59
Alan,

SQL Server 2005 SP2 CTP was released last week. MS added logon triggers. This will help you with problem.

See my follow up post on my blog

http://www.vandeputte.org/2006/11/sql-server-logon-triggers-part-2.html
Post #322620
Posted Wednesday, March 19, 2008 4:03 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: General Forum Members
Last Login: Tuesday, November 20, 2012 8:25 PM
Points: 6, Visits: 191
Can you please upload the scripts again. I can't find them under the URL you have listed.
thanks



Post #471986
Posted Friday, February 27, 2009 1:20 AM
Grasshopper

GrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopper

Group: General Forum Members
Last Login: Saturday, September 11, 2010 6:52 AM
Points: 21, Visits: 45
Thanks for your offer this article.

I met some errors after running your scripts; ERRORLOG memessageike this...

...
2009-02-27 17:07:35.01 spid14s Error: 9644, Severity: 16, State: 14.
2009-02-27 17:07:35.01 spid14s An error occurred in the service broker message dispatcher, Error: 15517 State: 1.

and I could resolve this problem for below code,
from http://social.technet.microsoft.com/Forums/en-US/sqlservicebroker/thread/a5af6e9a-f3b6-4b73-ae3d-95238502d28f/
ALTER AUTHORIZATION ON DATABASE::[My_DB_Name] TO [SA];

It works fine. I like it. :)
Post #665541
Posted Tuesday, April 14, 2009 4:15 AM
Valued Member

Valued MemberValued MemberValued MemberValued MemberValued MemberValued MemberValued MemberValued Member

Group: General Forum Members
Last Login: Monday, January 27, 2014 5:19 AM
Points: 55, Visits: 210
Hi,

Did you implement this logon trigger in a production heavy environment ?

I am asking this because i read few articles about big problems with logon triggers in heavy environments, sql instances crushes few times.
Post #696397
Posted Thursday, March 04, 2010 1:46 PM
SSC Journeyman

SSC JourneymanSSC JourneymanSSC JourneymanSSC JourneymanSSC JourneymanSSC JourneymanSSC JourneymanSSC Journeyman

Group: General Forum Members
Last Login: Wednesday, July 18, 2012 6:40 AM
Points: 75, Visits: 265
I implemented the event notification fo rlogin as in Frederick's article.
It work fine.

Now I want to only insert rows for certain loginname's.

I made another stored procedure with an IF statement in the stored proc that only inserts if the loginname is not in a list that I provide. If it is, I roll back and break.
I alter queue with status = off for the old stored proc, then alter queue with status = on fo rthe new proc.

What happens is I get one row that stays in the queue when I let someone log in that should be INSERTED into the table and no further INSERTS occur.

This is the new stored proc:
SET ANSI_NULLS ON
GO
SET QUOTED_IDENTIFIER ON
GO

ALTER PROCEDURE [dbo].[proc_log_user_logins_new]
AS
SET NOCOUNT ON;

DECLARE @message_body XML,
@message_type_name NVARCHAR(256),
@dialog UNIQUEIDENTIFIER ;

--Endless loop
WHILE (1 = 1)
BEGIN
BEGIN TRANSACTION ;

-- Receive the next available message

WAITFOR (
RECEIVE TOP(1)
@message_type_name=message_type_name,
@message_body=message_body,
@dialog = conversation_handle
FROM log_user_logins_queue
), TIMEOUT 2000

--Rollback and exit if no messages were found
IF (@@ROWCOUNT = 0)
BEGIN
ROLLBACK TRANSACTION ;
BREAK ;
END ;

--End conversation of end dialog message
IF (@message_type_name = 'http://schemas.microsoft.com/SQL/ServiceBroker/EndDialog')
BEGIN
PRINT 'End Dialog received for dialog # ' + cast(@dialog as nvarchar(40)) ;
END CONVERSATION @dialog ;
END ;
ELSE

IF CAST(@message_body.query('/EVENT_INSTANCE/LoginName/text()') AS VARCHAR(100))
NOT IN ('m58467','ITSERVICES\M10077','patrol_ssuser','patrol_ssadmin')
BEGIN
ROLLBACK TRANSACTION ;
BREAK ;
END ;
BEGIN
INSERT INTO log_user_logins (
EventTime,
EventType,
LoginName,
HostName,
NTUserName,
NTDomainName,
Success,
FullLog )
VALUES
(
CAST(CAST(@message_body.query('/EVENT_INSTANCE/PostTime/text()') AS VARCHAR(64)) AS DATETIME),
CAST(@message_body.query('/EVENT_INSTANCE/EventType/text()') AS VARCHAR(100)),
CAST(@message_body.query('/EVENT_INSTANCE/LoginName/text()') AS VARCHAR(100)),
CAST(@message_body.query('/EVENT_INSTANCE/HostName/text()') AS VARCHAR(100)),
CAST(@message_body.query('/EVENT_INSTANCE/NTUserName/text()') AS VARCHAR(100)),
CAST(@message_body.query('/EVENT_INSTANCE/NTDomainName/text()') AS VARCHAR(100)),
CAST(CAST(@message_body.query('/EVENT_INSTANCE/Success/text()') AS VARCHAR(64)) AS INTEGER),
@message_body)
END

COMMIT TRANSACTION
END


Any help would be greatly appreciated.
I am not sure how to properly code rows I receive , but do not want to insert or keep them in the queue.

The row in the queue:
select * from log_user_logins_queue

1 0 13 D19B6C5A-C927-DF11-9A25-001A64C552F2 D29B6C5A-C927-DF11-9A25-001A64C552F2 6 log_user_logins_service 65539 http://schemas.microsoft.com/SQL/Notifications/PostEventNotification 2 http://schemas.microsoft.com/SQL/Notifications/EventNotification 4 X 0x

I think the problem is what is stated in books online for receive statement:

"The RECEIVE statement removes received messages from the queue unless the queue specifies message retention. When the RETENTION setting for the queue is ON, the RECEIVE statement
updates the status column to 1 and leaves the messages in the queue. When a transaction that contains a RECEIVE statement rolls back, all changes to the queue within the transaction are also rolled back, returning messages to the queue."

my retention is the default (off).



Post #877143
Posted Thursday, August 26, 2010 1:36 AM
Grasshopper

GrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopperGrasshopper

Group: General Forum Members
Last Login: Wednesday, March 12, 2014 9:42 AM
Points: 10, Visits: 204
The script is working fine. But the table is keep on updating without any new logon event occurs. Also, it is not working for add_role_member server event.

Any help in this?
Post #975409
« Prev Topic | Next Topic »

Add to briefcase 12»»

Permissions Expand / Collapse