A SQL Server capability for tracking what happens on the server and in its databases. Events land in a file or the Windows Application or Security log, ready for an agent to collect.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SQL Server Audit in context, with comparison tables and the common traps.
Terms in this definition
- SQL Server
The relational database from Microsoft that organisations host and run themselves, in their own data centres or on VMs. Its engine also sits underneath the Azure SQL services and SQL database in Fabric.
- Capability
Something that a person, organisation or system is able to do.
- RAMP
The approach used by the Cloud Adoption Framework's Manage methodology to structure cloud operations: teams, duties, processes and tools. It divides what the central platform handles from what each workload handles.
- Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
Related terms
- Database audit specification
Says which database-level actions or action groups SQL Server Audit should record, for example
SELECT ON SCHEMA::HR BY public; each database can have one per audit. Server-level groups go in a server audit specification. - FAILED_LOGIN_GROUP
SQL Server audit action group, scoped to the server, that records failed logins to the instance. The recommended Azure SQL Database groups don't include it.
- SQL Managed Instance auditing
On Azure SQL Managed Instance, a single SQL Server Audit server audit spans every database. Targets are Blob storage as .xel files (TO URL), or Log Analytics or Event Hubs (TO EXTERNAL_MONITOR).