Capturing data values in audit log.
Posted in 2010
Topics: Security, Permissions & Auditing
I am trying to set up a process using ONAUDIT to monitor the data manipulation
activites of a few select users.
Is there any way of retreiving the before and after data values associated
with the updates, deletes, and inserts? I've had no problem setting up the
onaudit process, but this information is not in the audit log.
Thanks.
I don't think that you can get the actual data that way. If you are using
11.50 you could use the Change Data Capture API to build a detail audit
facility of your own and it will use far less resources than the Secure
Audit facility.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
IIUG Board of Directors (art@iiug.org)
See you at the 2010 IIUG Informix Conference
April 25-28, 2010
Overland Park (Kansas City), KS
www.iiug.org/conf
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Wed, May 5, 2010 at 3:50 PM, ROGERS PATTERSON <
rogers.patterson@arkansas.gov> wrote:
> I am trying to set up a process using ONAUDIT to monitor the data
> manipulation
> activites of a few select users.
>
> Is there any way of retreiving the before and after data values associated
> with the updates, deletes, and inserts? I've had no problem setting up the
> onaudit process, but this information is not in the audit log.
>
> Thanks.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--001636e0a7d7da0f4b0485de2e7c
Informix Onaudit utility does not support rows auditing.
That's only supposed to audit the database events, like DML commands,
and it doesn't log the "old / new" row values.
If that's your need, I suggest that you use a trigger to monitor the row
changes, and
then record it on another table, ok?
Best regards.
Em Qua, 2010-05-05 Ã s 15:50 -0400, ROGERS PATTERSON escreveu:
> I am trying to set up a process using ONAUDIT to monitor the data
manipulation
> activites of a few select users.
>
> Is there any way of retreiving the before and after data values associated
> with the updates, deletes, and inserts? I've had no problem setting up the
> onaudit process, but this information is not in the audit log.
>
> Thanks.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Hi
Yes we have a tool to do this. Please see
http://www.lintel.co.uk/infotrace/index.php
Regards
David Linthwaite
Lintel Software Consultancy Ltd
IBM Business Partner (www.lintel.co.uk)
Tel.: 01244 357250
Fax.: 01244 357248
mailto:dlinthwaite@lintel.co.uk
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of ROGERS
PATTERSON
Sent: 05 May 2010 20:51
To: ids@iiug.org
Subject: Capturing data values in audit log. [20023]
I am trying to set up a process using ONAUDIT to monitor the data
manipulation
activites of a few select users.
Is there any way of retreiving the before and after data values associated
with the updates, deletes, and inserts? I've had no problem setting up the
onaudit process, but this information is not in the audit log.
Thanks.
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
Hello Alexandre.
I'm a bit confused about your statements. You say onaudit does not support
rows auditing but on the other hand you say it supports DML commands.
Just for clarification, the audit facility can record read row (RDRW),
insert row (INRW), update row (UPRW) and delete row (DLRW) events.
Each one will store on the audit log file just the table (partnum/tabid?)
and the rowid. It does not store the values as you wrote.
So it's not a solution for the kind of tasks being discussed.
Triggers can be a solution if the idea is not to audit privileged users (who
can disable them for example). Change data capture is another as already
mentioned, and then some external tools.
Regards.
On Wed, May 5, 2010 at 9:57 PM, Alexandre Marini
<amarini@fazenda.ms.gov.br>wrote:
> Informix Onaudit utility does not support rows auditing.
>
> That's only supposed to audit the database events, like DML commands,
> and it doesn't log the "old / new" row values.
>
> If that's your need, I suggest that you use a trigger to monitor the row
> changes, and
> then record it on another table, ok?
>
> Best regards.
>
> Em Qua, 2010-05-05 Ã s 15:50 -0400, ROGERS PATTERSON escreveu:
>
> > I am trying to set up a process using ONAUDIT to monitor the data
> manipulation
> > activites of a few select users.
> >
> > Is there any way of retreiving the before and after data values
> associated
> > with the updates, deletes, and inserts? I've had no problem setting up
> the
> > onaudit process, but this information is not in the audit log.
> >
> > Thanks.
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--0016e6d7ea7bc578160485e12127