Re: Sniffer Decode for Informix
Posted in 2003
Hv u looked into the "onaudit" facility of the database. Pls check the
Trusted facility manual for more information. If you hit the right balance
of the events you want to audit/log you might get away without too much of
a performance hit.
HTH
Thanx much,
Rajib Sarkar
Advisory Software Engineer (RAS)
IBM Data Management Group
Ph : (602)-217-2100
Fax: (602)-217-2100
T/L : 667-2100
As long as you derive inner help and comfort from anything, keep it --
Mahatma Gandhi
bobby_medus@admin
istaff.com (Bobby To: informix-list@iiug.org
Medus) cc:
Sent by: Subject: Sniffer Decode for Informix
owner-informix-li
st@iiug.org
09/29/2003 02:14
PM
Please respond to
bobby_medus
Hello All,
We are currently running 7.31.UC3XE on an AIX 4.3.3 server. One of
our goals is to be able to identify all connections/sql statements and
log them to a file for security monitoring. I know that I can capture
a snapshot of this information from the sysmaster tables however this
only tells me what is running at the time the statement(s) run. If we
could capture the packet information as it comes across the wire we
would be able to log that and {hopefully} not be too intrusive on the
users.
What we are really hopeing to find is the smart users that have
figured out they can connect to our database with dbaccess or excel
via ODBC and put a stop to them.
99.9% of our connections come from a propriatary application and this
application contains the majority of our security. It is my
understanding that I-Spy was tried here without much success. I have
downloaded the INFSPY from IIUG but it looks like it would be a pretty
heavy hit on performance for my 200+ user base.
There is a push to get 9.4 here before end of Q1 next year but not
sure what that will buy us at this point.
We are running sql power tools but it tends to eat up 100+MB of memory
on the server and has caused performance hits during crunch times.
Thank you all very much for any information you might have.
Bobby Medus
sending to informix-list