Re: ONAUDIT or trigger & st.or. procedure
Posted in 2004
Topics: Stored Procedures & SPL, Security, Permissions & Auditing, Triggers, Constraints & Referential Integrity
Steve,
thak for your explanations, but that was not the point of my question(s). It is
"silly" for me to track changes for all tables and I (customer) is interested in
10 % (or less) of total tables number.
Second problem is "cryptic" output of ONAUDIT.
My customer asks me for example: "How and when change customer record for
custmer 'ABC Company'?" What can I do then? I have to find tabid for customer
table in systables, find the rowid of particular row and then find information
in ONAUDIT output. All of that is not a big problem. The biggest problem is
deleting of row. What can I do with rowid of deleted row?
nebojsa
On Fri, 27 Feb 2004 14:50:17 +0100, Steve <regnus@netscape.net> wrote:
>Hi Nebojsa,
>
>You get some info about secure-audting based on IDS 2000 (V9.21):
>
>At first it is important to start audting with: onaudit -l 1.
>You can stop it with command: onaudit -l 0
>
>All parameters will be stored in $INFORMIXDIR/aaodir/adtcfg-File.
>
>"onaudit -c" shows the audit-configuration.
>Then you must set the auditpath: onaudit -p >path<. With the command
>onaudit -s 10000, yout will set the size of the auditfile. If the file>his 10000 byte, the server will create a new file in the auditpath.
>
>After this you have to create a auditusermask:
>
>onaudit -a -u (usermask) -e +DLRW>
>-e means: Event DLRW: delete row
>You can find some details in "Trusted and Facility" Manual for IDS2000
>Part. No 000-6214.
>
>onshowaudit -u (user) -f [auditfile] shows what happend on the system.
>
>Ok ....
>
>Steve
>
>Nebojsa Sevo schrieb:
>> Steve,
>> I read manual for Informix 7.3 carefully. Just take a look into 9.3 manul and
>> didn't find any differences.
>> I try onaudit on 7.3 but some customers have 9.3.
>>
>> Nebojsa
>> On Thu, 26 Feb 2004 10:50:19 +0100, Steve <regnus@netscape.net> wrote:
>>
>>
>>>Hi Nebojsa,
>>>
>>>which Informix-Version ?
>>>
>>>Steve
>>>
>>>Nebojsa Sevo schrieb:
>>>
>>>>My customer have request to monitor update / delete activities on some tables. I
>>>>read Trusted Facility Manual. Problem with onaudit utility is that its output is
>>>>not "human readable" and it can't work on table level.
>>>>I know how to get table name from tabid and how to get data from rowid but I am
>>>>not sure that it is right way.
>>>>If I will use triggers and stored procedures problem is that I have to change
>>>>them every time I change table definition.
>>>>If anybody has experience with "monitoring DB activity" or suggestions, please
>>>>share it with me.
>>>>
>>>>Thanks in advance
>>>>
>>>>Nebojsa
>>>>------------------------------------
>>>>Remove spam block (DELETE_) to reply
>>>
>>
>> ------------------------------------
>> Remove spam block (DELETE_) to reply
------------------------------------
Remove spam block (DELETE_) to reply
Hi Nebojsa,
You can do nothing with rowid of a deleted row. But there is a solution
for your problem:
You can create a trigger-routine in case of deleting row from a table.
You must do this for any table in yout database. The best way is to
create a new database like the database which is checked with onaudit.
here an example for a trigger:
create trigger <tr_del_tablename> delete on <tablename>
REFERENCING old as pre
FOR EACH ROW
(insert into newdatabase:newtab1
(f1,f2 .......)
VALUSE
pre.f1,pre.f2 ...., current ---> Timestamp of delete, user----> User,
who delete the row)
So you can see in the second database who delete the row at that time
you see in yout audit-file.
Steve
Nebojsa Sevo schrieb:
> Steve,
> thak for your explanations, but that was not the point of my question(s). It is
> "silly" for me to track changes for all tables and I (customer) is interested in
> 10 % (or less) of total tables number.
> Second problem is "cryptic" output of ONAUDIT.
> My customer asks me for example: "How and when change customer record for
> custmer 'ABC Company'?" What can I do then? I have to find tabid for customer
> table in systables, find the rowid of particular row and then find information
> in ONAUDIT output. All of that is not a big problem. The biggest problem is
> deleting of row. What can I do with rowid of deleted row?
>
> nebojsa
> On Fri, 27 Feb 2004 14:50:17 +0100, Steve <regnus@netscape.net> wrote:
>
>
>>Hi Nebojsa,
>>
>>You get some info about secure-audting based on IDS 2000 (V9.21):
>>
>>At first it is important to start audting with: onaudit -l 1.
>>You can stop it with command: onaudit -l 0
>>
>>All parameters will be stored in $INFORMIXDIR/aaodir/adtcfg-File.
>>
>>"onaudit -c" shows the audit-configuration.
>>Then you must set the auditpath: onaudit -p >path<. With the command
>>onaudit -s 10000, yout will set the size of the auditfile. If the file>>his 10000 byte, the server will create a new file in the auditpath.
>>
>>After this you have to create a auditusermask:
>>
>>onaudit -a -u (usermask) -e +DLRW>>
>>-e means: Event DLRW: delete row
>>You can find some details in "Trusted and Facility" Manual for IDS2000
>>Part. No 000-6214.
>>
>>onshowaudit -u (user) -f [auditfile] shows what happend on the system.
>>
>>Ok ....
>>
>>Steve
>>
>>Nebojsa Sevo schrieb:
>>
>>>Steve,
>>>I read manual for Informix 7.3 carefully. Just take a look into 9.3 manul and
>>>didn't find any differences.
>>>I try onaudit on 7.3 but some customers have 9.3.
>>>
>>>Nebojsa
>>>On Thu, 26 Feb 2004 10:50:19 +0100, Steve <regnus@netscape.net> wrote:
>>>
>>>
>>>
>>>>Hi Nebojsa,
>>>>
>>>>which Informix-Version ?
>>>>
>>>>Steve
>>>>
>>>>Nebojsa Sevo schrieb:
>>>>
>>>>
>>>>>My customer have request to monitor update / delete activities on some tables. I
>>>>>read Trusted Facility Manual. Problem with onaudit utility is that its output is
>>>>>not "human readable" and it can't work on table level.
>>>>>I know how to get table name from tabid and how to get data from rowid but I am
>>>>>not sure that it is right way.
>>>>>If I will use triggers and stored procedures problem is that I have to change
>>>>>them every time I change table definition.
>>>>>If anybody has experience with "monitoring DB activity" or suggestions, please
>>>>>share it with me.
>>>>>
>>>>>Thanks in advance
>>>>>
>>>>>Nebojsa
>>>>>------------------------------------
>>>>>Remove spam block (DELETE_) to reply
>>>>
>>>------------------------------------
>>>Remove spam block (DELETE_) to reply
>>
>
> ------------------------------------
> Remove spam block (DELETE_) to reply
--
Ihre bevorzugten Shops, hilfreiche Einkaufs-Hilfen und gro'artige
Geschenk Ideen. Erleben Sie das Vergn'gen online einzukaufen mit
Shop@Netscape! http://shopping.netscape.de/shopping/