SQL Server 2005 Logon Triggers

  • F Vandeputte

    Old Hand

    Points: 356

    Comments posted to this topic are about the content posted at http://www.sqlservercentral.com/columnists/FVandeputte/sqlserver2005logontriggers.asp

  • Yelena Varshal

    SSC-Dedicated

    Points: 34207

    This is a good article!

    Question: the stored procedure LogginProc is doing the endless loop waiting for the logon event description to be queued and when it finds one it pulls the information from the queue. Is it really a trigger? I can do the similar thing with the traces. You just set up a server-side trace with logging to the trace file. Than the logon events will be logged to the trace file. Then you can select from the trace file into any table or you may select to keep this info in the trace file because you can query it too by fn_trace_gettable. I do understand that we will have to wait until trace file rolls over to get the information but it will be logged anyway.

    But in general, this article is a very good and easy to understand example on how to use the Service Broker.

     

     

    Regards,Yelena Varsha

  • F Vandeputte

    Old Hand

    Points: 356

    Yelena,

    You are right, you can get the same results by running a trace and saving it to a table. However I think event notifications are more robust and more flexible.

    I named the article SQL Server Logon triggers, refering to Oracle. But on SQL Server they are not really triggers.

    Kind regards,

    Frederik

  • alan ding

    Valued Member

    Points: 70

    but how to you disable unwanted logon like determine who from which workstation using which program. service broker will not kill the other one right?

  • F Vandeputte

    Old Hand

    Points: 356

    Alan,

    SQL Server 2005 SP2 CTP was released last week. MS added logon triggers. This will help you with problem.

    See my follow up post on my blog

    http://www.vandeputte.org/2006/11/sql-server-logon-triggers-part-2.html

  • cnappoly

    SSC Enthusiast

    Points: 100

    Can you please upload the scripts again. I can't find them under the URL you have listed.

    thanks

  • tsohr

    SSC Enthusiast

    Points: 103

    Thanks for your offer this article.

    I met some errors after running your scripts; ERRORLOG memessageike this...

    ...

    2009-02-27 17:07:35.01 spid14s Error: 9644, Severity: 16, State: 14.

    2009-02-27 17:07:35.01 spid14s An error occurred in the service broker message dispatcher, Error: 15517 State: 1.

    and I could resolve this problem for below code,

    from http://social.technet.microsoft.com/Forums/en-US/sqlservicebroker/thread/a5af6e9a-f3b6-4b73-ae3d-95238502d28f/

    ALTER AUTHORIZATION ON DATABASE::[My_DB_Name] TO [SA];

    It works fine. I like it. 🙂

  • Victor Shahar

    Mr or Mrs. 500

    Points: 502

    Hi,

    Did you implement this logon trigger in a production heavy environment ?

    I am asking this because i read few articles about big problems with logon triggers in heavy environments, sql instances crushes few times.

  • sgambale

    SSCommitted

    Points: 1709

    I implemented the event notification fo rlogin as in Frederick's article.

    It work fine.

    Now I want to only insert rows for certain loginname's.

    I made another stored procedure with an IF statement in the stored proc that only inserts if the loginname is not in a list that I provide. If it is, I roll back and break.

    I alter queue with status = off for the old stored proc, then alter queue with status = on fo rthe new proc.

    What happens is I get one row that stays in the queue when I let someone log in that should be INSERTED into the table and no further INSERTS occur.

    This is the new stored proc:

    SET ANSI_NULLS ON

    GO

    SET QUOTED_IDENTIFIER ON

    GO

    ALTER PROCEDURE [dbo].[proc_log_user_logins_new]

    AS

    SET NOCOUNT ON;

    DECLARE @message_body XML,

    @message_type_name NVARCHAR(256),

    @dialog UNIQUEIDENTIFIER ;

    --Endless loop

    WHILE (1 = 1)

    BEGIN

    BEGIN TRANSACTION ;

    -- Receive the next available message

    WAITFOR (

    RECEIVE TOP(1)

    @message_type_name=message_type_name,

    @message_body=message_body,

    @dialog = conversation_handle

    FROM log_user_logins_queue

    ), TIMEOUT 2000

    --Rollback and exit if no messages were found

    IF (@@ROWCOUNT = 0)

    BEGIN

    ROLLBACK TRANSACTION ;

    BREAK ;

    END ;

    --End conversation of end dialog message

    IF (@message_type_name = 'http://schemas.microsoft.com/SQL/ServiceBroker/EndDialog')

    BEGIN

    PRINT 'End Dialog received for dialog # ' + cast(@dialog as nvarchar(40)) ;

    END CONVERSATION @dialog ;

    END ;

    ELSE

    IF CAST(@message_body.query('/EVENT_INSTANCE/LoginName/text()') AS VARCHAR(100))

    NOT IN ('m58467','ITSERVICES\M10077','patrol_ssuser','patrol_ssadmin')

    BEGIN

    ROLLBACK TRANSACTION ;

    BREAK ;

    END ;

    BEGIN

    INSERT INTO log_user_logins (

    EventTime,

    EventType,

    LoginName,

    HostName,

    NTUserName,

    NTDomainName,

    Success,

    FullLog )

    VALUES

    (

    CAST(CAST(@message_body.query('/EVENT_INSTANCE/PostTime/text()') AS VARCHAR(64)) AS DATETIME),

    CAST(@message_body.query('/EVENT_INSTANCE/EventType/text()') AS VARCHAR(100)),

    CAST(@message_body.query('/EVENT_INSTANCE/LoginName/text()') AS VARCHAR(100)),

    CAST(@message_body.query('/EVENT_INSTANCE/HostName/text()') AS VARCHAR(100)),

    CAST(@message_body.query('/EVENT_INSTANCE/NTUserName/text()') AS VARCHAR(100)),

    CAST(@message_body.query('/EVENT_INSTANCE/NTDomainName/text()') AS VARCHAR(100)),

    CAST(CAST(@message_body.query('/EVENT_INSTANCE/Success/text()') AS VARCHAR(64)) AS INTEGER),

    @message_body)

    END

    COMMIT TRANSACTION

    END

    Any help would be greatly appreciated.

    I am not sure how to properly code rows I receive , but do not want to insert or keep them in the queue.

    The row in the queue:

    select * from log_user_logins_queue

    1 0 13 D19B6C5A-C927-DF11-9A25-001A64C552F2 D29B6C5A-C927-DF11-9A25-001A64C552F2 6 log_user_logins_service 65539 http://schemas.microsoft.com/SQL/Notifications/PostEventNotification 2 http://schemas.microsoft.com/SQL/Notifications/EventNotification 4 X 0x

    I think the problem is what is stated in books online for receive statement:

    "The RECEIVE statement removes received messages from the queue unless the queue specifies message retention. When the RETENTION setting for the queue is ON, the RECEIVE statement

    updates the status column to 1 and leaves the messages in the queue. When a transaction that contains a RECEIVE statement rolls back, all changes to the queue within the transaction are also rolled back, returning messages to the queue."

    my retention is the default (off).

  • manoj.ks

    Old Hand

    Points: 338

    The script is working fine. But the table is keep on updating without any new logon event occurs. Also, it is not working for add_role_member server event.

    Any help in this?

  • qingniaohappy

    SSC Rookie

    Points: 34

    I know this is a pertty aged thread, but still helps a lot to me.

    One issue i running into is, how to clean up history data in Logging table on daily/hour basis? Our environment has heavy activities, 10,0000 rows inserted int Logging table per hour.

    I was wandering to restart Service Broker's conversation and truncate log table, just fail to manage the conversation on the right way.

    Could someone kindly shed some lights on this? I'm a idiot on Service Broker:(

    Thanks so much!

  • qingniaohappy

    SSC Rookie

    Points: 34

    Hi guys, just to follow up my finds. We can directly truncate the logging table to remove raw data.

    To end the conersation to stop event notification, I use code below:

    USE msdb;

    GO

    DECLARE

    @conversation_handle uniqueidentifier,

    @ended_count int;

    SET @ended_count = 0;

    DECLARE old_endpoints CURSOR LOCAL FAST_FORWARD FOR

    SELECT conversation_handle

    FROM sys.conversation_endpoints

    WHERE

    far_service IN('LoggingService');

    OPEN old_endpoints;

    WHILE 1 = 1

    BEGIN

    FETCH NEXT FROM old_endpoints INTO @conversation_handle;

    IF @@FETCH_STATUS = -1 BREAK;

    END CONVERSATION @conversation_handle WITH CLEANUP;

    SET @ended_count = @ended_count + 1;

    IF @ended_count % 10000 = 0

    BEGIN

    RAISERROR('Cleanup progress: %d conversations ended', 0, 1, @ended_count) WITH NOWAIT;

    END

    END

    CLOSE old_endpoints;

    DEALLOCATE old_endpoints;

    And to restart it, re-create it on the target database:

    CREATE EVENT NOTIFICATION Logging_Event_Notification

    ON SERVER

    FOR AUDIT_LOGIN, AUDIT_LOGIN_FAILED--, AUDIT_LOGOUT

    TO SERVICE 'LoggingService', 'current database'

    GO

Viewing 12 posts - 1 through 12 (of 12 total)

You must be logged in to reply to this topic. Login to reply