Since agent are installed on the OS that the DB sits on, your best course of action is to monitor on the OS itself.
Few things you can do are:
- Ensure proper audit trails are in place to ensure any agent manipulation is tracked.
- Setup monitoring on the OS to ensure that the service/executable is running
A few self protection built in is to enable certificate based communication between agent and GW but thats more about encryption in transist.
You can also setup rules on siem for DAM/DBF when an agent does not sent traffic after a certain time.
------------------------------
Sarvesh Lad
Tech Lead @ On-Prem Managed Services (WAF, DAM, DRA & Sonar)
------------------------------