Call: +44 (0)1904 557620 Call
Blog

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "Expert Oracle Practices: Oracle database administration from the oak table"] [Next entry: "Oracle's new Oracle database security and compliance solution"]

Nice Summary of setting up audit options



I noticed a nice post on Robert Geier's blog a while ago and made a note to link to it from here. The post is titled " http://blog.contractoracle.com/2009/09/enable-oracle-auditing-before-you-need.html - (broken link) Enable Oracle auditing BEFORE you need it." which of course carries a lot of true sentiments. The article is quite long and suffers from not being easy to read as all of the text and the code is all in the same font but percevere (probably thats the wrong spelling but GM doesnt have a built in spell checker - yet!).

The article is a fast ride through lots of options; turn on audit, sys audit, audit options, some forensics ideas, querying the audit trail, using statspack, database vault, audit vault, FGA, checksumming, flashback, log miner, system triggers, AWR, Materialised view logs, trace,DML triggers, even DBMS_SYSTEM.KSDWRT, alert logs and even the scheduler logs. This is a great article that contains a lot of valuable data on what you can do for free in terms of auditing and monitoring your database. Well worth a read.