I am getting DROP table commands and not able to capture the IP Source.Can some one help me how to capture Source IP and user ID if I Receive any such command

Can you specify if you are running managed or self-hosted and what version number?

thank you for using SingleStore and reaching out to us. With regard to the question, can you enabled the audit logging on your database : Audit Logging Levels so that you firstly, you can tell who was logged in into the systems and running the query.

Additionally, if you are using the cloud service, either the traffic should be coming in from the private link endpoint or it should be one of the IP in the firewall rules specified on the database cluster.

