`
itspace
  • 浏览: 978376 次
  • 性别: Icon_minigender_1
  • 来自: 杭州
社区版块
存档分类
最新评论

浅用Oracle审计

阅读更多
以下仅为测试经过,不做详细说明
SQL>  show parameter audit

NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest                      string      /opt/ora11g/app/admin/db11g/ad
                                                 ump
audit_sys_operations                 boolean     FALSE
audit_syslog_level                   string
audit_trail                          string      DB
SQL> alter system set audit_sys_operations=true;
alter system set audit_sys_operations=true
                 *
ERROR at line 1:
ORA-02095: specified initialization parameter cannot be modified


SQL> show parameter spfile

NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
spfile                               string      /opt/ora11g/app/product/11.1/d
                                                 bs/spfiledb11g.ora
SQL> alter system set audit_sys_operations=true scope=spfile;

System altered.

SQL> exit
Disconnected from Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
[ora11g@mchz ~]$ ls -l  /opt/ora11g/app/admin/db11g/adump
total 516
...
-rw-r----- 1 ora11g dba  657 Apr 16  2010 ora_9541.aud
-rw-r----- 1 ora11g dba 2564 Sep  4  2008 pmon_341.aud
-rw-r----- 1 ora11g dba  888 Sep  4  2008 pmon_8728.aud
[ora11g@mchz ~]$ pwd
/home/ora11g
[ora11g@mchz ~]$ cd  /opt/ora11g/app/admin/db11g/adump
[ora11g@mchz adump]$ sqlplus "/as sysdba"

SQL*Plus: Release 11.1.0.6.0 - Production on Tue Nov 16 15:30:31 2010

Copyright (c) 1982, 2007, Oracle.  All rights reserved.


Connected to:
Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options

SQL> shutdown immediate
Database closed.
Database dismounted.
ORACLE instance shut down.
SQL> startup
ORACLE instance started.

Total System Global Area  313159680 bytes
Fixed Size                  2143984 bytes
Variable Size             281020688 bytes
Database Buffers           25165824 bytes
Redo Buffers                4829184 bytes
Database mounted.
Database opened.
SQL> show parameter audit;

NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest                      string      /opt/ora11g/app/admin/db11g/ad
                                                 ump
audit_sys_operations                 boolean     TRUE
audit_syslog_level                   string
audit_trail                          string      DB
SQL> conn scott/tiger
Connected.
SQL> audit select on emp;

Audit succeeded.

SQL> select * from emp;
select * from emp
              *
ERROR at line 1:
ORA-28365: wallet is not open


SQL> audit select on dept;

Audit succeeded.

SQL> select * from dept;

    DEPTNO DNAME          LOC
---------- -------------- -------------
        10 ACCOUNTING     NEW YORK
        20 RESEARCH       DALLAS
        30 SALES          CHICAGO
        40 OPERATIONS     BOSTON

SQL> select OWNER,OBJECT_NAME,OBJECT_TYPE,DEL,INS,SEL,UPD from dba_obj_audit_opts;
select OWNER,OBJECT_NAME,OBJECT_TYPE,DEL,INS,SEL,UPD from dba_obj_audit_opts
                                                          *
ERROR at line 1:
ORA-00942: table or view does not exist


SQL> conn /as sysdba
Connected.
SQL> select OWNER,OBJECT_NAME,OBJECT_TYPE,DEL,INS,SEL,UPD from dba_obj_audit_opts;

OWNER                          OBJECT_NAME
------------------------------ ------------------------------
OBJECT_TYPE             DEL   INS   SEL   UPD
----------------------- ----- ----- ----- -----
SCOTT                          DEPT
TABLE                   -/-   -/-   S/S   -/-

SCOTT                          EMP
TABLE                   -/-   -/-   S/S   -/-


SQL> desc dba_obj_audit_opts;
Name                                      Null?    Type
----------------------------------------- -------- ----------------------------
OWNER                                              VARCHAR2(30)
OBJECT_NAME                                        VARCHAR2(30)
OBJECT_TYPE                                        VARCHAR2(23)
ALT                                                VARCHAR2(3)
AUD                                                VARCHAR2(3)
COM                                                VARCHAR2(3)
DEL                                                VARCHAR2(3)
GRA                                                VARCHAR2(3)
IND                                                VARCHAR2(3)
INS                                                VARCHAR2(3)
LOC                                                VARCHAR2(3)
REN                                                VARCHAR2(3)
SEL                                                VARCHAR2(3)
UPD                                                VARCHAR2(3)
REF                                                CHAR(3)
EXE                                                VARCHAR2(3)
CRE                                                VARCHAR2(3)
REA                                                VARCHAR2(3)
WRI                                                VARCHAR2(3)
FBK                                                VARCHAR2(3)

SQL> select count(*) from dba_audit_trail;

  COUNT(*)
----------
      1547

SQL> desc dba_audit_trail;
Name                                      Null?    Type
----------------------------------------- -------- ----------------------------
OS_USERNAME                                        VARCHAR2(255)
USERNAME                                           VARCHAR2(30)
USERHOST                                           VARCHAR2(128)
TERMINAL                                           VARCHAR2(255)
TIMESTAMP                                          DATE
OWNER                                              VARCHAR2(30)
OBJ_NAME                                           VARCHAR2(128)
ACTION                                    NOT NULL NUMBER
ACTION_NAME                                        VARCHAR2(28)
NEW_OWNER                                          VARCHAR2(30)
NEW_NAME                                           VARCHAR2(128)
OBJ_PRIVILEGE                                      VARCHAR2(16)
SYS_PRIVILEGE                                      VARCHAR2(40)
ADMIN_OPTION                                       VARCHAR2(1)
GRANTEE                                            VARCHAR2(30)
AUDIT_OPTION                                       VARCHAR2(40)
SES_ACTIONS                                        VARCHAR2(19)
LOGOFF_TIME                                        DATE
LOGOFF_LREAD                                       NUMBER
LOGOFF_PREAD                                       NUMBER
LOGOFF_LWRITE                                      NUMBER
LOGOFF_DLOCK                                       VARCHAR2(40)
COMMENT_TEXT                                       VARCHAR2(4000)
SESSIONID                                 NOT NULL NUMBER
ENTRYID                                   NOT NULL NUMBER
STATEMENTID                               NOT NULL NUMBER
RETURNCODE                                NOT NULL NUMBER
PRIV_USED                                          VARCHAR2(40)
CLIENT_ID                                          VARCHAR2(64)
ECONTEXT_ID                                        VARCHAR2(64)
SESSION_CPU                                        NUMBER
EXTENDED_TIMESTAMP                                 TIMESTAMP(6) WITH TIME ZONE
PROXY_SESSIONID                                    NUMBER
GLOBAL_UID                                         VARCHAR2(32)
INSTANCE_NUMBER                                    NUMBER
OS_PROCESS                                         VARCHAR2(16)
TRANSACTIONID                                      RAW(8)
SCN                                                NUMBER
SQL_BIND                                           NVARCHAR2(2000)
SQL_TEXT                                           NVARCHAR2(2000)
OBJ_EDITION_NAME                                   VARCHAR2(30)

SQL> exec dbms_fga.add_policy(object_schema=>'scott', object_name=> 'dept', policy_name=> 'check_dept_audit',statement_types => 'SELECT');

PL/SQL procedure successfully completed.

SQL> select * from scott.dept;

    DEPTNO DNAME          LOC
---------- -------------- -------------
        10 ACCOUNTING     NEW YORK
        20 RESEARCH       DALLAS
        30 SALES          CHICAGO
        40 OPERATIONS     BOSTON

SQL> select db_user,sql_text from dba_fga_audit_trail;

no rows selected

SQL> exec dbms_fga.enable_policy(object_schema=>'scott', object_name=> 'dept', policy_name=> 'check_t_audit');
BEGIN dbms_fga.enable_policy(object_schema=>'scott', object_name=> 'dept', policy_name=> 'check_t_audit'); END;

*
ERROR at line 1:
ORA-28102: policy does not exist
ORA-06512: at "SYS.DBMS_FGA", line 77
ORA-06512: at line 1


SQL> exec dbms_fga.enable_policy(object_schema=>'scott', object_name=> 'dept', policy_name=> 'check_dept_audit');

PL/SQL procedure successfully completed.

SQL> select * from scott.dept;

    DEPTNO DNAME          LOC
---------- -------------- -------------
        10 ACCOUNTING     NEW YORK
        20 RESEARCH       DALLAS
        30 SALES          CHICAGO
        40 OPERATIONS     BOSTON

SQL>  select db_user,sql_text from dba_fga_audit_trail;

no rows selected

SQL> conn scott/tiger
Connected.
SQL> exec dbms_fga.add_policy(object_schema=>'scott', object_name=> 'dept', policy_name=> 'check_dept_audit',statement_types => 'SELECT');
BEGIN dbms_fga.add_policy(object_schema=>'scott', object_name=> 'dept', policy_name=> 'check_dept_audit',statement_types => 'SELECT'); END;

      *
ERROR at line 1:
ORA-06550: line 1, column 7:
PLS-00201: identifier 'DBMS_FGA' must be declared
ORA-06550: line 1, column 7:
PL/SQL: Statement ignored


SQL>  select * from scott.dept;

    DEPTNO DNAME          LOC
---------- -------------- -------------
        10 ACCOUNTING     NEW YORK
        20 RESEARCH       DALLAS
        30 SALES          CHICAGO
        40 OPERATIONS     BOSTON

SQL> conn /as sysdba
Connected.
SQL> select db_user,sql_text from dba_fga_audit_trail;

DB_USER
------------------------------
SQL_TEXT
--------------------------------------------------------------------------------
SCOTT
select * from scott.dept


SQL> exit
Disconnected from Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
[ora11g@mchz adump]$ pwd
/opt/ora11g/app/admin/db11g/adump
[ora11g@mchz adump]$ ls -rtl
total 540
...
-rw-r----- 1 ora11g dba 1225 Nov 16 15:31 ora_8262.aud
-rw-r----- 1 ora11g dba 1223 Nov 16 15:31 ora_8766.aud
-rw-r----- 1 ora11g dba 2734 Nov 16 15:37 ora_17316.aud
-rw-r----- 1 ora11g dba  834 Nov 16 15:38 ora_4230.aud
[ora11g@mchz adump]$ more ora_4230.aud
Audit file /opt/ora11g/app/admin/db11g/adump/ora_4230.aud
Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options
ORACLE_HOME = /opt/ora11g/app/product/11.1
System name:    Linux
Node name:      mchz
Release:        2.6.18-53.el5xen
Version:        #1 SMP Mon Nov 12 02:46:57 EST 2007
Machine:        x86_64
Instance name: db11g
Redo thread mounted by this instance: 1
Oracle process number: 18
Unix process pid: 4230, image: oracle@mchz (TNS V1-V3)

Tue Nov 16 15:37:57 2010
ACTION : 'CONNECT'
DATABASE USER: '/'
PRIVILEGE : SYSDBA
CLIENT USER: ora11g
CLIENT TERMINAL: pts/1
STATUS: 0

Tue Nov 16 15:38:04 2010
ACTION : 'select db_user,sql_text from dba_fga_audit_trail'
DATABASE USER: '/'
PRIVILEGE : SYSDBA
CLIENT USER: ora11g
CLIENT TERMINAL: pts/1
STATUS: 0

[ora11g@mchz adump]$ sqlplus "/as sysdba"

SQL*Plus: Release 11.1.0.6.0 - Production on Tue Nov 16 15:48:30 2010

Copyright (c) 1982, 2007, Oracle.  All rights reserved.


Connected to:
Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production
With the Partitioning, OLAP, Data Mining and Real Application Testing options

SQL> show parameter audit

NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest                      string      /opt/ora11g/app/admin/db11g/ad
                                                 ump
audit_sys_operations                 boolean     TRUE
audit_syslog_level                   string
audit_trail                          string      DB
分享到:
评论

相关推荐

    深入浅出Oracle: DBA入门、进阶与诊断案例.pdf

    《深入浅出Oracle:DBA入门、进阶与诊断案例》是一本专为数据库管理员(DBA)设计的Oracle技术指南。这本书详细介绍了Oracle数据库管理的基础知识,中级技能以及高级故障诊断技巧,旨在帮助读者从新手到专家逐步提升...

    深入浅出Oracle

    《深入浅出Oracle》这本书是Oracle数据库管理员(DBA)学习和提升技能的重要参考资料。它涵盖了Oracle数据库的基础知识、进阶技巧以及故障诊断方法,旨在帮助读者全面理解和掌握Oracle数据库的管理与维护。以下是对该...

    oracle教程--深入浅出oracle学习资料

    Oracle教程——深入浅出Oracle学习资料 Oracle数据库系统是全球广泛应用的关系型数据库管理系统,由甲骨文公司(Oracle Corporation)开发。本教程旨在为初学者和有经验的IT专业人士提供全面、深入的Oracle知识,...

    深入浅出oracle ebs之核心功能.pdf

    《深入浅出Oracle EBS之核心功能:Distribution应用模块》一文由黄建华撰写,旨在详尽解析Oracle E-Business Suite(简称Oracle EBS)中Distribution模块的核心功能与最佳技术实践。该文档创建于2005年4月12日,最新...

    深入浅出Oracle.rar

    "深入浅出Oracle"这个压缩包文件显然是一份关于Oracle数据库的学习资料,可能是书籍的PDF电子版,旨在帮助读者全面理解Oracle的各个方面。 Oracle数据库的核心特性包括: 1. **数据存储与管理**:Oracle采用行式...

    深入浅出Oracle:DBA入门、进阶与诊断案例

    此外,书中的"深入浅出"特点意味着作者将复杂的Oracle技术用通俗易懂的语言进行阐述,避免了技术书籍常见的理论化和难以理解的问题。这样的写作风格使得无论是新手还是有经验的DBA,都能从中受益。 总之,《深入浅...

    深入浅出Oracle:DBA入门

    本书《深入浅出Oracle:DBA入门、进阶与诊断案例》由盖国强编著,由人民邮电出版社出版,旨在为初学者提供全面的Oracle数据库管理入门知识,并为有一定经验的DBA提供进阶技巧和实际案例分析。 首先,本书开篇可能会...

    《深入浅出Oracle:DBA入门、进阶与诊断案例》电子书

    此外,书中还会讨论Oracle的安全管理,包括用户权限、角色、审计和加密技术。这有助于保护数据库免受未经授权的访问和潜在的数据泄露。 本书适合不同层次的Oracle DBA阅读,无论是初学者还是有经验的专业人士,都能...

    oracle DBA必看【深入浅出Oracle】

    《深入浅出Oracle》是Oracle数据库管理员(DBA)学习的重要参考资料,它涵盖了Oracle数据库的基础知识、进阶技术和故障诊断案例。对于想要深入了解Oracle DBA工作的人来说,这本书提供了全面且实践性强的学习路径。 ...

    深入浅出Oracle: DBA入门、进阶与诊断案例. .pdf

    《深入浅出Oracle:DBA入门、进阶与诊断案例》是数据库领域的经典之作,由知名专家eagle精心编著,旨在帮助读者全面理解和掌握Oracle数据库管理(DBA)的各项技能。Oracle DBA是一个关键角色,负责维护Oracle数据库...

    深入浅出Oracle:DBA入门、进阶与诊断案例(盖国强)

    《深入浅出Oracle:DBA入门、进阶与诊断案例》是盖国强老师的一部专为Oracle数据库管理员(DBA)编写的权威教程。这本书以其深入浅出的讲解方式,成为了许多Oracle初学者和进阶者的学习宝典。下面我们将深入探讨其中...

    深入浅出Oracle EBS之核心功能(DIS)

    ### 深入浅出Oracle EBS之核心功能(DIS) #### 一、概述 Oracle E-Business Suite (EBS) 是一个全面的企业资源规划(ERP)解决方案,它集成了财务管理、供应链管理、项目组合与项目管理、风险管理与合规、企业绩效...

    深入浅出Oracle: DBA入门、进阶与诊断案例(原生PDF)

    本书会讲解Oracle的身份验证机制、权限管理、审计功能,以及如何制定和实施安全策略。同时,还会涉及备份与恢复技术,包括RMAN(Recovery Manager)的使用、数据泵导出导入、以及如何规划和执行灾难恢复计划,以确保...

Global site tag (gtag.js) - Google Analytics