Bridge Specifications
Vendor | Microsoft |
Tool Name | SQL Server Database |
Tool Version | 7.0 to 15.x (2019) |
Tool Web Site | http://msdn.microsoft.com/en-us/sqlserver/aa937724.aspx |
Supported Methodology | [Relational Database] Multi-Model, Data Store (Physical Data Model, Stored Procedure Expression Parsing) via JDBC API |
SPECIFICATIONS
Tool: Microsoft / SQL Server Database version 7.0 to 15.x (2019) via JDBC API
See http://msdn.microsoft.com/en-us/sqlserver/aa937724.aspx
Metadata: [Relational Database] Multi-Model, Data Store (Physical Data Model, Stored Procedure Expression Parsing)
Component: JdbcMicrosoftSqlServer version 11.2.0
DISCLAIMER
This import bridge requires internet access to download third-party libraries:
- such as https://repo.maven.apache.org/maven2/ to download open source third-party libraries,
- and more sites for other third-party software such as database specific JDBC drivers.
The downloaded third-party libraries are stored into $HOME/data/download/MIMB/
- If HTTPS fails, the import bridge then tries with HTTP.
- If a proxy is used to access internet, you must configure that proxy in the JRE (see the -j option in the Miscellaneous parameter).
- If the import bridge does not have full access to internet, that $HOME/data/download/MIMB/ directory can be copied from another server with internet access where the command $HOME/bin/MIMB.sh (or .bat) -d can be used to download all third-party libraries used by all bridges at once.
By running this import bridge, you hereby acknowledge responsibility for the license terms and any potential security vulnerabilities from these downloaded third-party software libraries.
OVERVIEW
This import bridge uses a JDBC connection to a Microsoft SQL Server database server to extract all its metadata (e.g. Schemas, Tables, Columns, Data Types.) and parse any SQL (e.g. Views, Stored Procedures) to produce the data flow lineage.
This import bridge imports the database server metadata as multi models with one model per schema. Further imports (incremental harvesting) will detect changes in schema to only import changed schemas (reusing already harvested unchanged schemas).
REQUIREMENTS
See the 'Driver location' parameter for any JDBC driver requirements.
See the PERMISSIONS section below.
Note that SQL Server no longer supports TLS v1 and v1.1 and instead requires TLS 1.2, for security reasons. In addition, JDK 11.0 disables any out of date TLS versions such as 1.0 and 1.1 by default.
https://support.microsoft.com/en-us/topic/kb3135244-tls-1-2-support-for-microsoft-sql-server-e4472ef8-90a9-13c1-e4d8-44aad198cdbe#:%7E:text=SQL%20Server%202019%20has%20the,to%20enable%20TLS%201.2%20support
Therefore, if SQL Server cannot be upgraded to TLS 1.2, then the JDK 11 configuration must be modified by editing the file: /MetaIntegration/jre/conf/security/java.security
and remove "TLSv1, TLSv1.1," in the following line:
- jdk.tls.disabledAlgorithms=SSLv3, TLSv1, TLSv1.1, RC4, DES, MD5withRSA, \
which should then look like:
- jdk.tls.disabledAlgorithms=SSLv3, RC4, DES, MD5withRSA, \
AUTHENTICATION
Database Authentication mode: specify values for 'User' and 'Password' parameters.
Windows Integrated Authentication mode: the 'User' and 'Password' parameters are not used, they should be left blank.
If MIMB is running as a regular application, the username/password credentials are inferred from the current process/session.
If MIMB is running as a Windows Service, the service configuration login will be used.
In order to configure MIMB to run as a service, navigate to the Windows Services Manager, right-click on the MIMB Application Server service, and go to the "Log On" tab to define an account by name under which the service will run.
When using the JDBC URL with Windows Integrated Security feature turned on (the Host parameter must include 'integratedSecurity=true'), the JDBC driver will automatically switch to SSL authentication.
PERMISSIONS
Any import bridge is warranted to be read only and only extracts metadata. Therefore the user of this import bridge requires much less permissions than classic users needing to read/write data.
The user should have at least the VIEW DEFINITION permission and a permission to CONNECT to the database.
FREQUENTLY ASKED QUESTIONS
Q: How to configure Integrated Authentication On Windows?
A: The JDBC URL specified in the Host parameter must include 'integratedSecurity=true' or other settings required by your configuration.
In addition, if the «driver location» value is empty (default), the bridge tries to download the mssql-jdbc_auth-<version>-<arch>.dll driver file from Maven.
Otherwise, copy the x64 version of mssql-jdbc_auth-<version>-<arch>.dll into the directory where the JDBC driver is installed that should match the value of the 'driver location' parameter.
Please check the official Microsoft documentation for details:
https://docs.microsoft.com/en-us/sql/connect/jdbc/building-the-connection-url?view=sql-server-2017#Connectingintegrated
Q: It seems that the server is not using a valid certificate, but a self-signed certificate, how may I resolve this?
A: There are several options available:
- Install a valid certificate on the database server
- Trust the server certificate by specifying trustServerCertificate=true under the 'Host' parameter
- Import the server certificate via the MIMB server by using MIRSetup (\Setup.bat -ch *Fully qualified domain name of server* -cp 1433), however this may not work if the MIMB Server is dependent on a Remote Harvesting Agent for import.
LIMITATIONS
Refer to the current general known limitations at https://metaintegration.com/Products/MIMB/Help/#!Documents/mimbknownlimitations.html
If a schema is defined using a system role, the bridge simply recognizes that schema as a system object because it was
created as a system object.
SUPPORT
Provide a troubleshooting package with:
- the debug log (can be set in the UI or in conf/conf.properties with MIR_LOG_LEVEL=6)
- the metadata backup if available (can be set in the Miscellaneous parameter with -backup option, although this common option is not implemented on all bridges for technical reasons).
Bridge Parameters
Parameter Name | Description | Type | Values | Default | Scope | ||||
Driver location | The file directory where the JDBC driver files are located. When the value is empty (default), the bridge tries to download the driver files from Maven. The default driver class name is 'com.microsoft.sqlserver.jdbc.SQLServerDriver'. If the driver specified has a different class name, specify that name using the -driver.className option in the Miscellaneous bridge parameter. |
DIRECTORY | |||||||
Host | The host name used by JDBC to connect to the database server (localhost by default) e.g. MyDatabaseServer.com or its IP address, e.g. 192.169.1.2 Pay close attention to semicolon and forward-slash placement within the Host URL specified. or its fully qualified JDBC connection string, e.g. jdbc:sqlserver://192.168.56.61:1433;databaseName=AdventureWorksDW;integratedSecurity=false; Azure SQL database requires a hostNameInCertificate when specified encrypt=true, e.g. jdbc:sqlserver://abc.database.windows.net:1433;encrypt=true;trustServerCertificate=false;hostNameInCertificate=*.database.windows.net;loginTimeout=30; If using Windows Integrated Security: - When using the hostname only, the Integrated Security feature is not used and the driver needs a 'User' and 'Password'. - When using the JDBC URL with Integrated Security turned on, the 'User' and 'Password' are not used (they should be left blank), and the driver automatically switches to using SSL. |
STRING | localhost | Mandatory | |||||
Port | The port used by JDBC to connect to the database server (1433 by default for Microsoft SQL Server). This parameter is ignored if the Host parameter is based on a fully qualified JDBC connection string that includes the port. In case of the Microsoft SQL Server database: For optimal connection performance, you should set the 'Port' option when you connect to a named instance. This will avoid a round trip to the server to determine the port number. If both a 'Port' option and 'Instance' option are used, the 'Port' option will take precedence and the 'Instance' option will be ignored. |
NUMERIC | |||||||
Instance | The SQL Server instance name. SQL Server allow for the installation of multiple database instances per server. Each instance is identified by a specific name. To connect to a named instance of SQL Server, you can either specify the port number of the named instance (preferred), or you can specify the instance name. |
STRING | |||||||
User | The user name used by JDBC to connect to the database server. This parameter is ignored if the Host parameter is based on a fully qualified JDBC connection string that includes the username. Refer to the PERMISSIONS section of this import bridge's main documentation. Also, for the Microsoft SQL Server specific bridge, if this parameter is empty, then it is assumed that integrated security is being used (see http://msdn.microsoft.com/en-us/library/ms378428.aspx#Connectingintegrated). In this case, this import bridge will attempt to connect with this type of signature: jdbc:sqlserver://; integratedSecurity=true instead of jdbc:sqlserver://; user=userid;password=userpassword However, in order for this to work, the user must have the sqljdbc_auth.dll available on the PATH environment variable. Also the version of the library must match the version of the sqljdbc4.jar that they are using. If using Windows Integrated Security: - When using the hostname only, the Integrated Security feature is not used and the driver needs a 'User' and 'Password'. - When using the JDBC URL with Integrated Security turned on, the 'User' and 'Password' are not used (they should be left blank), and the driver automatically switches to using SSL. |
STRING | |||||||
Password | The user password used by JDBC to connect to the database server. | PASSWORD | |||||||
Databases | The subset of database instances to import expressed as a comma (,) or semicolon (;) separated list of databases' names, e.g. database1; database2 All database instances are imported if that list is empty. You can use SQL LIKE patterns to identify names of databases. See the Schema parameter documentation for details. |
REPOSITORY_SUBSET | |||||||
Schemas | The subset of schemas to import expressed as a semicolon separated list of schemas' names, e.g. schema1; schema2 This parameter also supports the dot annotation in combination with * wildcards to enable specification of what groups of objects to import, e.g. database1.schema1; database2.*; All accessible user schemas are imported if that list is empty. All system schemas (e.g. SysAdmin) and objects are ignored by default. If system schemas are needed, use the Miscellaneous parameter option -system.objects.import. Schema name patterns using the syntax rules used by the LIKE operator in SQL: - Inclusion syntax: using % or *, e.g. A%; %B; %C%; D - start with A or - end with B or - contain C or - equal D - Exclusion syntax: using NOT, e.g. A%; %B; NOT %SYS; NOT 'SYS%' - WHERE (name like A% or name like %B) - and (name NOT like %SYS) - and (name NOT like 'SYS%') - Special characters: ^ $ * + ? | \ ( ) [ ] { } whitespace enclose this name in square brackets and escape special characters, e.g. OneWord%; [Two\sWords.*]; [Dollar\$] |
REPOSITORY_SUBSET | |||||||
Tables | The subset of "Tables" to import expressed as a semicolon separated list of objects in schemas, like table, view, function, e.g. table1; table2; view1; function1 This parameter also supports the [database.][schema.]table dot annotation in combination with * wildcards to enable specification of what groups of objects to import, e.g. database1.schema1.table1; database1.*.table2; database1.schema3.*; All user objects that the bridge supports are imported if that list is empty. All system tables (e.g. SysAdmin) and objects are ignored by default. If system tables are needed, use the Miscellaneous parameter option -system.objects.import. Table name patterns using a SQL like expression syntax: - Inclusion syntax: using % or *, e.g. A%; %B; %C%; D - start with A or - end with B or - contain C or - equal D - Exclusion syntax: using NOT, e.g. A%; %B; NOT %SYS; NOT 'SYS%' - WHERE (name like A% or name like %B) - and (name NOT like %SYS) - and (name NOT like 'SYS%') - Special characters: ^ $ * + ? | \ ( ) [ ] { } whitespace enclose this name in square brackets and escape special characters, e.g. OneWord%; [Two\sWords.*]; [Dollar\$] |
STRING | |||||||
Stored procedure details | Controls the amount of details imported from stored procedures: 'Signature' The name and parameters of stored procedures 'Code, signature' The above plus code 'Lineage, code, signature' The above plus data lineage derived from the code 'None' stored procedure details are not included. |
ENUMERATED |
|
Signature | |||||
Import indexes | Controls the import of Indexes: 'False' Indexes are not imported 'True' Indexes are imported |
BOOLEAN |
|
False | |||||
Miscellaneous | INTRODUCTION Specify miscellaneous options starting with a dash and optionally followed by parameters, e.g. -connection.cast MyDatabase1="MICROSOFT SQL SERVER" Some options can be used multiple times if applicable, e.g. -connection.rename NewConnection1=OldConnection1 -connection.rename NewConnection2=OldConnection2; As the list of options can become a long string, it is possible to load it from a file which must be located in ${MODEL_BRIDGE_HOME}\data\MIMB\parameters and have the extension .txt. In such case, all options must be defined within that file as the only value of this parameter, e.g. ETL/Miscellaneous.txt JAVA ENVIRONMENT OPTIONS -java.memory <Java Memory's maximum size> (previously -m) 1G by default on 64bits JRE or as set in conf/conf.properties, e.g. -java.memory 8G -java.memory 8000M -java.parameters <Java Runtime Environment command line options> (previously -j) This option must be the last one in the Miscellaneous parameter as all the text after -java.parameters is passed "as is" to the JRE, e.g. -java.parameters -Dname=value -Xms1G The following option must be set when a proxy is used to access internet (this is critical to access https://repo.maven.apache.org/maven2/ and exceptionally a few other tool sites) in order to download the necessary third-party software libraries. Note: The majority of proxies are concerned with encrypting (HTTPS) the outside (of the company) traffic and trust the inside traffic that can access proxy over HTTP. In this case, an HTTPS request reaches the proxy over HTTP where the proxy HTTPS-encrypts it. -java.parameters -java.parameters -Dhttp.proxyHost=127.0.0.1 -Dhttp.proxyPort=3128 -Dhttp.proxyUser=user -Dhttp.proxyPassword=pass MODEL IMPORT OPTIONS -model.name <model name> Override the model name, e.g. -model.name "My Model Name" -prescript <script name> This option allows running a script before the bridge execution. The script must be located in the bin directory (or as specified with M_SCRIPT_PATH in conf/conf.properties), and have .bat or .sh extension. The script path must not include any parent directory symbol (..). The script should return exit code 0 to indicate success, or another value to indicate failure. For example: -prescript "script.bat arg1 arg2" -postscript <script name> This option allows running a script after successful execution of the bridge. The script must be located in the bin directory (or as specified with M_SCRIPT_PATH in conf/conf.properties), and have .bat or .sh extension. The script path must not include any parent directory symbol (..). The script should return exit code 0 to indicate success, or another value to indicate failure. For example: -postscript "script.bat arg1 arg2" -cache.clear Clears the cache before the import, and therefore will run a full import without incremental harvesting. If the model was not changed and the -cache.clear parameter is not used (incremental harvesting), then a new version will not be created. If the model was not changed and the -cache.clear parameter is set (full source import instead of incremental), then a new version will be created. -backup <directory> Allows to save the input metadata for further troubleshooting. The provided <directory> must be empty. -restore <directory> Specify the backup <directory> to be restored. DATA CONNECTION OPTIONS Data Connections are produced by the import bridges typically from ETL/DI and BI tools to refer to the source and target data stores they use. These data connections are then used by metadata management tools to connect them (metadata stitching) to their actual data stores (e.g. databases, file system, etc.) in order to produce the full end to end data flow lineage and impact analysis. The name of each data connection is unique by import model. The data connection names used within DI/BI design tools are used when possible, otherwise connection names are generated to be short but meaningful such as the database / schema name, the file system path, or Uniform Resource Identifier (URI). The following option allows to manipulate connections. These options replaces the legacy options -c, -cd, and -cs. -connection.cast ConnectionName=ConnectionType Casts a generic database connection (e.g. ODBC/JDBC) to a precise database type (e.g. ORACLE) for SQL Parsing, e.g. -connection.cast "My Database"="MICROSOFT SQL SERVER". The list of supported data store connection types includes: ACCESS APACHE CASSANDRA DB2/UDB DENODO GOOGLE BIGQUERY HIVE MYSQL NETEZZA ORACLE POSTGRESQL PRESTO REDSHIFT SALESFORCE SAP HANA SNOWFLAKE MICROSOFT SQL AZURE MICROSOFT SQL SERVER SYBASE SQL SERVER SYBASE AS ENTERPRISE TERADATA VECTORWISE HP VERTICA -connection.rename OldConnection=NewConnection Renames an existing connection to a new name, e.g. -connection.rename OldConnectionName=NewConnectionName Multiple existing database connections can be renamed and merged into one new database connection, e.g. -connection.rename MySchema1=MyDatabase -connection.rename MySchema2=MyDatabase -connection.split oldConnection.Schema1=newConnection Splits a database connection into one or multiple database connections. A single database connection can be split into one connection per schema, e.g. -connection.split MyDatabase All database connections can be split into one connection per schema, e.g. -connection.split * A database connection can be explicitly split creating a new database connection by appending a schema name to a database, e.g. -connection.split MyDatabase.schema1=MySchema1 -connection.map SourcePath=DestinationPath Maps a source path to destination path. This is useful for file system connections when different paths points to the same object (directory or file). On Hadoop, a process can write into a CSV file specified with the HDFS full path, but another process reads from a Hive table implemented (external) by the same file specified using a relative path with default file name and extension, e.g. -connection.map /user1/folder=hdfs://host:8020/users/user1/folder/file.csv On Linux, a given directory (or file) like /data can be referred to by multiple symbolic links like /users/john and /users/paul, e.g. -connection.map /data=/users/John -connection.map /data=/users/paul On Windows, a given directory like C:\data can be referred to by multiple network drives like M: and N:, e.g. -connection.map C:\data=M:\ -connection.map C:\data=N:\ -connection.casesensitive ConnectionName... Overrides the default case insensitive matching rules for the object identifiers inside the specified connection, provided the detected type of the data store by itself supports this configuration (e.g. Microsoft SQL Server, MySql etc.), e.g. -connection.casesensitive "My Database" -connection.caseinsensitive ConnectionName... Overrides the default case sensitive matching rules for the object identifiers inside the specified connection, provided the detected type of the data store by itself supports this configuration (e.g. Microsoft SQL Server, MySql etc.), e.g. -connection.caseinsensitive "My Database" -connection.level AggregationLevel Specifies the aggregation level for the external connections, e.g.-connection.level catalog The list of the supported values: server catalog schema (default) JDBC DATABASE OPTIONS -system.objects.import (previously -s) Imports all system objects (that are skipped by default). -synonyms.ignore (previously -synonyms) Ignores the synonyms when importing, therefore reducing the size of the model when a large number synonyms exist. -data.dictionary.server <database identification name> (previously -server.name) Sets a server name for the data dictionary to use for extracting tables and view definitions. In a multitenant Container Database (CDB), the metadata for data dictionary tables and view definitions is stored only at the root level. However, each Pluggable Database (PDB) has its own set of data dictionary tables and views for the database objects contained in the PDB. It is possible that some dba_ views are not available because they are not applicable. -driver.fetch.size <number of rows> (previously -f) The database driver fetch size in number of rows, e.g. -driver.fetch.size 100 -model.split (previously -multiModel) Splits a large database model into multi models (e.g. one schema per model). Warning: this is a system option managed by the application calling this import bridge and should not be set by users. -driver.className The full name (including the package name) of the Java class that implements the JDBC driver interface. -comment.udp Import any database object comments as a user defined property with the specified name instead of the comment property. |
STRING |
Bridge Mapping
Meta Integration Repository (MIR) Metamodel (based on the OMG CWM standard) |
"Microsoft SQL Server Database (via JDBC)" Metamodel JdbcMicrosoftSqlServer |
Mapping Comments |
Name | Name | |
Argument | Procedure Column | The stored procedure parameters are stored in the arguments |
Description | Comments on the column | |
Kind | Type | The kind of parameter |
Name | Name | |
Association | Exported Keys | |
Aggregation | True if all the attributes in the Exported Key a+C105re in the Primary Key | |
AssociationRole | Exported Keys | |
ExtraConstraint | Update Rule, Delete Rule | |
Multiplicity | Nullable property of the columns of the Exported Key | |
Source | Based on the multiplicity of each role | |
AssociationRoleNameMap | Exported Keys | The rolename map is created if the columns in the primary and foreign keys are different |
Attribute | Table Column | |
Comment | Comments on the column | |
InitialValue | Default value | |
Name | Name | |
Optional | Based on the nullable property | |
PhysicalName | Name | |
Position | Position | If position is not provided, the order in which the attributes are retrieved is used. |
BaseType | Types | |
DataType | Data Type | See datatype conversion array |
Length | Size | |
Name | The name is computed from the datatype | |
PhysicalName | Name | |
Scale | Maximum scale | |
CandidateKey | Index, Primary Key | |
Name | Name | |
PhysicalName | Name | |
UniqueKey | Non-Unique property | |
Class | Table | of type "TABLE" |
Comment | Comments on the table | |
CppClassType | Set to ENTITY | |
CppPersistent | Set to True | |
Name | Name | |
PhysicalName | Name | |
ClassDiagram | Schema | A class diagram is created for each package and contains all the elements of the package |
DerivedType | Column | Table column, stored procedure column SQL View column or type |
DataType | Data Type | See datatype conversion array |
Length | Size | |
Name | The name is computed from the datatype | |
PhysicalName | Name | |
Scale | Decimal digits | |
UserDefined | True for Type | |
DesignPackage | Schema | A Package is created for each retrieved schema. If there is no schema a default package is created. |
Name | Name | Set to "Schema" if there is no schema or the schema has no name. |
ForeignKey | Exported Keys | |
Name | Name | |
PhysicalName | Name | |
Index | Index, Primary Key, Exported Keys | |
Clustered | Index type | true if index type is tableIndexClustered |
Name | Name | |
PhysicalName | Name | |
IndexMember | Index Member, Key Member | |
Position | Position in the Index or key | |
SortOrder | Ascending/descending order | |
SQLViewAttribute | View Column | |
Comment | Comments on the column | |
Name | Name | |
PhysicalName | Name | |
Position | Ordinal position | |
SQLViewEntity | Table | of type "VIEW" |
Comment | Comments on the table | |
Name | Name | |
PhysicalName | Name | |
StoreModel | Catalog | The model is built using the elements contained in the catalog (The database name used for catalog) |
Name | Name | Set to MSSQLServer database name. |
StoredProcedure | Stored Procedure | |
Description | Comments on the stored procedure | |
Name | Name | |
Synonym | Table Synonym | |
Name | Name |