Skip to content

What is kAudit?

kAudit is a SQL Audit Monitoring Platform built by Kovoco. It connects to your SQL Server's native audit output and provides continuous monitoring, observability, and analysis of database activity across your organization.

Who is it for?

RoleHow kAudit helps
Database AdministratorsAudit event triage, query attribution, activity analysis, and instance health monitoring
Security AnalystsReal-time audit monitoring with AI-enriched context, correlation, and timeline analysis
IT ManagersExecutive summaries, trend analysis, and team access management

Key capabilities

  • Continuous monitoring — Audit events are captured within seconds of being written to the .sqlaudit file.
  • Audit activity explorer — Search, filter, and drill into every SQL Server audit event from a single dashboard.
  • AI-powered analysis — AI-powered event enrichment, pattern detection, and remediation guidance.
  • Programmatic API access — Query your audit data via a REST API for integration with dashboards, SIEMs, and automation workflows.
  • Real-time notifications — Push alerts to your portal, email, Microsoft Teams, Slack, or any webhook endpoint.
  • Multi-tenant — Manage multiple SQL instances across your organization with full data isolation.

Architecture overview

┌──────────────────────┐     ┌────────────────────┐     ┌─────────────────────────┐
│  Your SQL Server     │     │  kAudit Agent       │     │  kAudit Platform        │
│  (on-prem / Azure VM)│     │  (Windows service)  │     │  (hosted on Azure)      │
│                      │────▶│                     │────▶│                         │
│  SQL Server Audit    │     │  Reads .sqlaudit    │     │  Analysis Engine        │
│  *.sqlaudit files    │     │  files from disk    │     │  Customer Portal        │
└──────────────────────┘     └────────────────────┘     │  Admin Portal           │
                                                         └─────────────────────────┘

The agent is a self-contained Windows service that reads SQL Server's native audit files (.sqlaudit) directly from disk — no SQL connection required for the default configuration. It streams events securely over HTTPS to the kAudit platform, where they are analyzed and surfaced in your portal.

What's next?

If you're a new subscriber, start here:

SQL Audit Monitoring, made simple.