KB2897633 - FIX: You cannot start an audit by using an "ALTER" statement in SQL Server 2012 or SQL Server 2014

Applies To
SQL Server 2012 Developer SQL Server 2012 Enterprise SQL Server 2012 Express SQL Server 2012 Standard SQL Server 2012 Web SQL Server 2014 Developer - duplicate (do not use) SQL Server 2014 Enterprise - duplicate (do not use) SQL Server 2014 Standard - duplicate (do not use)

Symptoms

Consider the following scenario:

  1. You have a computer that is running Microsoft SQL Server 2012 or SQL Server 2014.
  2. You create an audit and many WHERE clauses that are larger than 3000 bytes.
  3. You try to start the audit by using an ALTER statement

In this scenario, the audit does not start, and you receive the following error message:

Note

Msg 102, Level 15, State 1, Line LineNumber
Incorrect syntax near 'SomeStrings'.
Msg 25711, Level 16, State 2, Line LineNumber
Failed to parse an event predicate.

NOTE: Please note that the issue here is that the syntax error is incorrectly raised in step 3, when you try to START the trace. This fix allows the error to be raised in the proper place, in step 2 where you CREATE an audit with WHERE clause greater than (>) 3000 characters. This fix does not change the WHERE predicate expression limit.

The predicate expression is still limited to 3000 characters. Please refer to predicate_expression in the following BOL article: ALTER SERVER AUDIT (Transact-SQL).

Resolution

The issue was first fixed in the following cumulative update of SQL Server.

Cumulative Update 1 for SQL Server 2014 /en-us/help/2931693

Cumulative Update 7 for SQL Server 2012 SP1 /en-us/help/2894115

About cumulative updates for SQL Server

Each new cumulative update for SQL Server contains all the hotfixes and all the security fixes that were included with the previous cumulative update. Check out the latest cumulative updates for SQL Server:

      

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.