SQL Server: Encrypted DDL Trigger to Track all Database Changes

I know, you guys are thinking that why we require DDL Trigger to track database changes in SQL Server.

SQL Server already has Changed Data Capture (CDC) and Audit option.
When we are talking about DDL Trigger, compare to other automated process this manual process is still preferred by SQL DBA because It is easy to use and manage.

A Database Administrator is also responsible for all different types of Database Security like: Database / Schema / Object level permission, Tracking object creation.

I have enabled SQL Server Audit for one of our production report server, but some time It does not work as per the expectation.

I have searched the alternate solution and found that we can create DDL trigger on a database to track the DDL operation of different objects.
We can also use DDL triggers to verify the result of SQL Server Audit.

Other take care points of DDL Trigger are:

Only SA or Admin user has to perform this stuff. The DBA should restrict other common database user to view or modify the DDL trigger.

It should be encrypted.

If our database is heavily loaded with tons of transaction, we should not create any type of DDL trigger on it.

Here, I am creating one encrypted DDL Trigger which tracks different types of object like:
Stored Procedure, Table, View, Function, Trigger, Sequence, Index.

Step to create Encrypted DDL Trigger:

First Create separate database:

Create one table which will hold all event information:

SELECT your application Database and create below encrypted DDL trigger:

If you require to enable DDL trigger on multiple database, execute DDL trigger one by one on each require a database.

Please do not create a DDL Trigger on [DDLChanges] database, that we have created in the first step which is for tracking purposes.

Now, perform any DDL action on your database and check [DDLChanges].[dbo].[tbl_TrackDDLChanges] table where you can find important information like: which SQL Query, who created, which host, what time, on which database and other.


Please share your ideas and opinions about this topic with me, your contribution will add true value to this topic.
If anyone has doubts on this topic then please do let me know by leaving comments or send me an email.

If you like this post, then please share it with others.
Please follow dbrnd.com, I will share my experience towards the success of Database Research and Development Activity.

I put up a post every day, please keep reading and learning.
Discover Yourself, Happy Blogging !
Anvesh M. Patel.

More from dbrnd.com

Leave a Reply

Be the First to Comment!

Notify of
avatar

wpDiscuz