经验首页 前端设计 程序设计 Java相关 移动开发 数据库/运维 软件/图像 大数据/云计算 其他经验
当前位置:技术经验 » 数据库/运维 » MS SQL Server » 查看文章
使用Server Trigger保护重要的数据库对象
来源:cnblogs  作者:东山絮柳仔  时间:2018/12/28 9:37:40  对本文有异议

一 .Server Trigger的简单介绍

在SQL Server数据库中,Server Trigger 是一种特殊类型的存储过程它可以对特定表、视图或存储中的必然事件自动响应,不由用户调用。创建触发器时对其进行定义,以便在对特定的数据库对象作特定类型的修改时执行,根据触发器定义的动作做出反应。

其主要被用在保持数据库对象的完整性方面。例如,防止数据库中已建好的表和存储过程被更改或删除。此外还可以 进行更改历史记录的追踪,查看表或存储被修改的记录。

Server Trigger比Database Trigger所管控的范围更广,可以管控Server下的所有Database的对象。

 

二. 主要表 及创建脚本

表Protected_Objects ,主要用来存储被保护的数据库对象,例如 表和存储过程。 字段 ActiveFlag设置为Y时有效,N是无效。

有新的数据库对象创建,最自动Insert一笔数据。

  1. CREATE TABLE [dbo].[Protected_Objects](
  2. [ServerIP] [varchar](100) NULL,
  3. [ServerName] [varchar](100) NULL,
  4. [DBName] [varchar](100) NULL,
  5. [ObjName] [varchar](100) NULL,
  6. [Objtype] [varchar](100) NULL,
  7. [Creator] [varchar](100) NULL,
  8. [ActiveFlag] [varchar](10) NULL,
  9. [TransDateTime] [datetime] NULL
  10. ) ON [PRIMARY]
  11.  
  12. GO

 

表DBTrigger_Log,主要存储数据库对象变动记录。

 

  1. CREATE TABLE [dbo].[DBTrigger_Log](
  2. [ServerIP] [varchar](20) NULL,
  3. [ServerName] [varchar](50) NULL,
  4. [DBName] [varchar](100) NULL,
  5. [ObjectName] [varchar](100) NULL,
  6. [ObjectType] [varchar](100) NULL,
  7. [EventType] [varchar](100) NULL,
  8. [HostName] [varchar](128) NULL,
  9. [AppName] [varchar](128) NULL,
  10. [EventData] [xml] NULL,
  11. [TransDateTime] [datetime] NULL,
  12. [Flag] [int] NULL DEFAULT ((0))
  13. ) ON [PRIMARY] TEXTIMAGE_ON [PRIMARY]
  14.  
  15. GO
  16.  
  17. SET ANSI_PADDING OFF
  18. GO
  19.  
  20. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'服务器IP' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'ServerIP'
  21. GO
  22.  
  23. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'服务器名称' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'ServerName'
  24. GO
  25.  
  26. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'数据库名称' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'DBName'
  27. GO
  28.  
  29. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'对象名称' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'ObjectName'
  30. GO
  31.  
  32. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'对象类型' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'ObjectType'
  33. GO
  34.  
  35. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'事件类型' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'EventType'
  36. GO
  37.  
  38. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'终端机器名' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'HostName'
  39. GO
  40.  
  41. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'名称' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'AppName'
  42. GO
  43.  
  44. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'触发事件xml' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'EventData'
  45. GO
  46.  
  47. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'发生时间' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'TransDateTime'
  48. GO
  49.  
  50. EXEC sys.sp_addextendedproperty @name=N'MS_Description', @value=N'是否上传' , @level0type=N'SCHEMA',@level0name=N'dbo', @level1type=N'TABLE',@level1name=N'DBTrigger_Log', @level2type=N'COLUMN',@level2name=N'Flag'
  51. GO

 

三. 创建Server Trigger的脚本

 

  1. USE [master]
  2. GO
  3.  
  4. /****** Object: DdlTrigger [ServerDBTrigger_ProtectObjects] Script Date: 2018/12/27 13:36:00 ******/
  5. SET ANSI_NULLS ON
  6. GO
  7.  
  8. SET QUOTED_IDENTIFIER ON
  9. GO
  10.  
  11.  
  12. /*###########################################################################################
  13. *Program*: <DB Trigger>
  14. *Description*: <Protect SQL key objects>
  15. *programer*: <>
  16. *Date*: 2015-12-03
  17. ---0001 2015-12-03 11:12 第一阶段期间只保留修改记录,暂时不阻止(不RollBack)
  18. ---0002 2015-12-03 15:32 增加发邮件的功能.
  19. ---0003 2015-12-04 14:20 出现set ANSI_PADDING Off后,还有(如果是script出来的表,其中有索引约束等,
  20. --- 需要Alter表时,就会报错。)代码时,@xEvent.query会报错。
  21. ##############################################################################################*/
  22. CREATE TRIGGER [ServerDBTrigger_DBA_ProtectObjects]
  23. ON ALL SERVER
  24. FOR DROP_TABLE,DROP_PROCEDURE,DROP_VIEW,DROP_FUNCTION,
  25. CREATE_TABLE,CREATE_PROCEDURE,CREATE_VIEW,CREATE_FUNCTION,
  26. ALTER_PROCEDURE,ALTER_VIEW,ALTER_TABLE,ALTER_FUNCTION,RENAME
  27. AS
  28. SET NOCOUNT ON ;
  29. BEGIN TRY
  30. DECLARE @ServerIP varchar(20)
  31. DECLARE @ServerName varchar(50)
  32. DECLARE @AppName nvarchar(128)
  33. DECLARE @HostName nvarchar(128)
  34. DECLARE @DBName varchar(100)
  35. DECLARE @ObjectName varchar(100)
  36. DECLARE @ObjectType varchar(100)
  37. DECLARE @EventType varchar(100)
  38. DECLARE @ObjectAction varchar(100)
  39. DECLARE @xEvent XML
  40. SET @xEvent = EVENTDATA()
  41. ----------------------0003 start ----------
  42. --Set @DBName=CONVERT(VARCHAR(100),@xEvent.query('data(/EVENT_INSTANCE/DatabaseName)'))
  43. --Set @ObjectName=CONVERT(VARCHAR(100),@xEvent.query('data(/EVENT_INSTANCE/ObjectName)'))
  44. --Set @ObjectType=CONVERT(VARCHAR(100),@xEvent.query('data(/EVENT_INSTANCE/ObjectType)'))
  45. --Set @ObjectAction=CONVERT(VARCHAR(100),@xEvent.query('data(/EVENT_INSTANCE/EventType)'))
  46. DECLARE @EventData varchar(MAX)
  47. SELECT @EventData=CONVERT(VARCHAR(MAX),@xEvent)
  48. SET @DBName= SUBSTRING (@EventData, CHARINDEX('<DatabaseName>',@EventData)+14, CHARINDEX('</DatabaseName>',@EventData)-CHARINDEX('<DatabaseName>',@EventData)-14)
  49. SET @ObjectName= SUBSTRING (@EventData, CHARINDEX('<ObjectName>',@EventData)+12, CHARINDEX('</ObjectName>',@EventData)-CHARINDEX('<ObjectName>',@EventData)-12)
  50. SET @ObjectType= SUBSTRING (@EventData, CHARINDEX('<ObjectType>',@EventData)+12, CHARINDEX('</ObjectType>',@EventData)-CHARINDEX('<ObjectType>',@EventData)-12)
  51. SET @ObjectAction= SUBSTRING (@EventData, CHARINDEX('<EventType>',@EventData)+11, CHARINDEX('</EventType>',@EventData)-CHARINDEX('<EventType>',@EventData)-11)
  52. SET @EventType=SUBSTRING(@EventData, CHARINDEX('<EventType>',@EventData)+11, CHARINDEX('</EventType>',@EventData)-CHARINDEX('<EventType>',@EventData)-11)
  53. ------------0003 end ---------------
  54. SELECT @HostName=HOST_NAME(),@AppName=APP_NAME()
  55. SELECT @ServerName = @@SERVERNAME
  56. SELECT @ServerIP = MIN(LOCAL_NET_ADDRESS) FROM SYS.DM_EXEC_CONNECTIONS WHERE LOCAL_NET_ADDRESS IS NOT NULL
  57. IF EXISTS(SELECT TOP 1 ObjName FROM Protected_Objects WITH(NOLOCK) WHERE ServerName = @@SERVERNAME AND DBName=@DBName AND ObjName=@ObjectName AND ActiveFlag='Y')
  58. BEGIN
  59. IF (@ObjectName LIKE 'TMP%')OR (/*@ObjectAction LIKE 'ALTER%' AND */@ObjectName LIKE '[_]%')
  60. BEGIN
  61. INSERT INTO DBTrigger_Log
  62. ( ServerIP ,ServerName ,DBName ,ObjectName ,ObjectType,EventType ,HostName , AppName ,[EventData] ,TransDateTime)
  63. VALUES ( @ServerIP ,@ServerName , @DBName , @ObjectName ,@ObjectType ,@EventType,@HostName ,@AppName ,@EventData , GETDATE())
  64. END
  65. ELSE
  66. BEGIN
  67. -----------------0001 start ---
  68. INSERT INTO DBTrigger_Log
  69. ( ServerIP ,ServerName ,DBName ,ObjectName ,ObjectType,EventType ,HostName , AppName ,[EventData] ,TransDateTime)
  70. VALUES ( @ServerIP ,@ServerName , @DBName , @ObjectName ,@ObjectType ,@EventType,@HostName ,@AppName ,@EventData , GETDATE())
  71. --Rollback TRANSACTION
  72. -----------------end --------
  73. -------------0002 begin ----------------
  74. DECLARE @Subject AS nvarchar(200)
  75. DECLARE @Body AS nvarchar(MAX)
  76. DECLARE @SPName AS nvarchar(MAX)
  77. SET @Subject = 'ServerDBTrigger-重要!;ServerIP:' + @ServerIP
  78. SET @SPName = ''
  79. SET @Body = '<html><body>Dear All,<br> <br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ServerName:' + @ServerName+ ' ; ServerIP:' + @ServerIP+ '上的object已被改动,请及时检查!!!
  80. <br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;You can get detail information from DBA_DBTrigger_Log. <br><br><table border=1 bgcolor=#aaff11>'
  81. SET @Body = @Body+ '<tr bgcolor=#ffaa11><td>ServerName</td><td>ServerIP</td><td>DBName</td><td>EventType</td><td>ObjectName</td><td>ObjectType</td><td>HostName </td><td>TransDateTime</td></tr>'
  82. SELECT @SPName = @SPName + '<tr bgcolor=#ffaa11><td>'+ CAST(@ServerName AS NVARCHAR(50))+ '</td><td>'+ CAST(@ServerIP AS NVARCHAR(50))+ '</td><td>' + CAST(@DBName AS NVARCHAR(50)) + '</td><td>'+ CAST(@EventType AS NVARCHAR(50))+ '</td><td>'+CAST(@ObjectName AS NVARCHAR(50))+ '</td><td>'+ CAST(@ObjectType AS NVARCHAR(20))+ '</td><td>'+ SUBSTRING(REPLACE(CAST(@HostName AS varchar(500)), CHAR(0), ''), 1, 500)+ '</td><td>'+ CONVERT(varchar(100), GETDATE(), 21)+ '</td></tr>'
  83. SET @Body = @Body + @SPName + '</table>'
  84.  
  85. SET @BODY=REPLACE(@BODY,'''','')
  86. IF REPLACE(@BODY,' ','')<>''
  87. BEGIN
  88. DECLARE @AllEmailToAddress varchar(3000)=''
  89. DECLARE @AllEmailCcAddress varchar(3000)=''
  90. DECLARE @Allprofile_name varchar(100)=''
  91. SELECT @AllEmailToAddress='收件人的地址'
  92. SELECT @AllEmailCcAddress='抄送人的地址'
  93.  
  94. SELECT TOP 1 @Allprofile_name=NAME FROM msdb.dbo.sysmail_profile ORDER BY profile_id
  95. EXEC msdb..sp_send_dbmail @profile_name = @Allprofile_name -- profile 名称
  96. ,@recipients = @AllEmailToAddress -- 收件人邮箱
  97. ,@copy_recipients=@AllEmailCcAddress
  98. ,@subject = @Subject -- 邮件标题
  99. ,@body = @BODY -- 邮件内容
  100. ,@body_format = 'HTML' -- 邮件格式
  101. ,@file_attachments=''
  102. END
  103. ------------- 0002 end ------------
  104. END
  105. END
  106. ----新建对象自动塞入保护表
  107. ELSE
  108. BEGIN
  109. --PRINT 3
  110. DELETE FROM Protected_Objects WHERE ServerName = @@SERVERNAME AND DBName=@DBName AND ObjName=@ObjectName
  111. IF @ObjectAction LIKE 'Create%' AND @AppName LIKE '%Microsoft SQL Server Management Studio%'
  112. AND @ObjectName NOT LIKE '[_]%' AND @ObjectName NOT LIKE 'TMP%'
  113. BEGIN
  114. INSERT INTO Protected_Objects
  115. VALUES ( @ServerIP, @ServerName, @DBName, @ObjectName,@ObjectType, @HostName, 'Y', GETDATE() )
  116. INSERT INTO DBTrigger_Log
  117. ( ServerIP ,ServerName ,DBName ,ObjectName ,ObjectType,EventType ,HostName , AppName ,[EventData] ,TransDateTime)
  118. VALUES ( @ServerIP ,@ServerName , @DBName , @ObjectName ,@ObjectType ,@EventType,@HostName ,@AppName ,@EventData , GETDATE())
  119. END
  120. ELSE IF @ObjectAction NOT LIKE 'Create%' AND @AppName LIKE '%Microsoft SQL Server Management Studio%' AND @ObjectName NOT LIKE '[_]%'
  121. BEGIN
  122. INSERT INTO DBTrigger_Log
  123. ( ServerIP ,ServerName ,DBName ,ObjectName ,ObjectType,EventType ,HostName , AppName ,[EventData] ,TransDateTime)
  124. VALUES ( @ServerIP ,@ServerName , @DBName , @ObjectName ,@ObjectType ,@EventType,@HostName ,@AppName ,@EventData , GETDATE())
  125. END
  126. END
  127. END TRY
  128. BEGIN CATCH
  129. PRINT '@ObjectName:'+@ObjectName
  130. PRINT '@ObjectType:'+@ObjectType
  131. PRINT ERROR_MESSAGE()
  132. ROLLBACK TRANSACTION
  133. END CATCH
  134. SET ANSI_NULLS OFF
  135.  
  136.  
  137. GO
  138.  
  139. SET ANSI_NULLS OFF
  140. GO
  141.  
  142. SET QUOTED_IDENTIFIER OFF
  143. GO
  144. ENABLE TRIGGER [ServerDBTrigger_ProtectObjects] ON ALL SERVER
  145. GO

 

四. 补充

创建Server Trigger 后,此时表Protected_Objects是空的,没有被保护的数据库对象。我们可以将数据库下面的对象批量插入。例如,我们将数据库XXXX下除 _和unuse开头之外的所有对象批量插入。其脚本如下:

  1. INSERT INTO Protected_Objects(DBName,ObjName,ObjType,Creator,ActiveFlag,TransDateTime)
  2. SELECT 'XXXXXX',Name, CASE xtype WHEN 'U' THEN 'Table' WHEN 'P' THEN 'Procedure' WHEN 'FN' THEN 'Function' WHEN 'TF' THEN 'Function' WHEN 'V' THEN 'View' END,
  3. HOST_NAME(),'Y' ,CONVERT(VARCHAR(10),DATEADD(DAY,-46,GETDATE()),120)
  4. FROM [XXXXXXX].dbo.sysobjects WHERE xtype IN ('U','P','FN','V','TF')
  5. AND name NOT LIKE '[_]%'
  6. AND name NOT LIKE 'unuse%'

 

 友情链接:直通硅谷  点职佳  北美留学生论坛

本站QQ群:前端 618073944 | Java 606181507 | Python 626812652 | C/C++ 612253063 | 微信 634508462 | 苹果 692586424 | C#/.net 182808419 | PHP 305140648 | 运维 608723728

W3xue 的所有内容仅供测试,对任何法律问题及风险不承担任何责任。通过使用本站内容随之而来的风险与本站无关。
关于我们  |  意见建议  |  捐助我们  |  报错有奖  |  广告合作、友情链接(目前9元/月)请联系QQ:27243702 沸活量
皖ICP备17017327号-2 皖公网安备34020702000426号