How to set up your FortiDB : Planning the network topology for database activity monitoring (DAM)
 
Planning the network topology for database activity monitoring (DAM)
Database activity monitoring (DAM) using the TCP/IP sniffer (also known as packet capture or network analyzer) is available for the appliance version of FortiDB only. It provides functions like policy-based activity auditing, activity profiling, and security alerts.
To use DAM with the TCP/IP sniffer, connect one or more of your FortiDB appliance's ports to the SPAN port of the switch that is connected to your database server. This configuration allows the appliance to monitor all traffic passing to and from the server.
See also
Tutorial: Monitoring a database table using the TCP/IP sniffer