fn_dblog can expose transaction-log records during a narrow investigation, but retention and missing user context make it a last resort.
Keeping a Change Log for Every Database
A change log for every database records what changed, when, why, and by whom, with a simple table and a habit of updating it.
Auditing SELECT Statements on Sensitive Tables
Auditing SELECT statements on sensitive tables needs a narrow database audit, protected files, volume checks, and active review.
Finding Unused Logins and Users Before an Audit
Review unused logins with password metadata, database mappings and activity capture, then use an owner approved disable-first plan.
Hunting Suspicious Objects After a SQL Server Compromise
Investigate a SQL Server compromise by preserving evidence and checking logins, startup procedures, Agent jobs, risky features, and changed objects.
SQL SERVER – Interesting Observation of Logon Trigger On All Servers
I created a Logon Trigger to audit every successful login for a client, and one login was recorded several times on different threads. The script and what I saw.
Reading the Default Trace
Reading the default trace can reveal recent object and configuration changes while its rolling files still retain the evidence.







