Skip to content

Database Activity Monitoring

Database Activity Monitoring records the queries and access events that occur in your connected databases — what was queried, by whom, when, and from where — and retains them as an audit trail for compliance and investigation. This is distinct from System Audit Log, which records administrative actions taken inside the ALTR platform itself, not activity in your connected databases. Database Activity Monitoring does not support Databricks data sources. Contact ALTR about audit-record retention duration.

  • Activity Monitoring Dashboard (Snowflake and OLTP) — View aggregated, read-only metrics on database activity.
  • Query Log (Snowflake and OLTP) — Search and review individual query audit records.
  • Custom Audit Logs (Snowflake only) — Extend Snowflake audit capture to activity types outside ALTR’s default coverage.
  • Audit Reports (OLTP only) — Generate and review formatted, attestable reports of database activity.
  • DAM Alerting (Snowflake and OLTP) — Configure rule-based notifications over database activity.

Snowflake activity is captured through the Snowflake Cloud Integration once columns and/or tags are connected, and capture is limited to SELECT queries on those connected columns; see Snowflake Integration Overview. OLTP capture is available through the sidecar and Security Intelligence Scout integrations, which can run alongside or instead of each other; set up at least one before you expect activity to appear. Running both against the same database captures activity twice; see Sidecar Integration Overview for detail.

Captured activity surfaces as aggregated metrics on the Activity Monitoring Dashboard and as individual, searchable records in the Query Log, which in turn feed DAM Alerting’s rule-based notifications and Audit Reports’ scheduled and on-demand compliance reports. Database Activity Monitoring data can be exported to a customer-owned Amazon S3 bucket for downstream tools.