IDS 12.10 onaudit configuration
Posted in 2016
User asked about enabling IDS 12.10 auditing on production with concerns about performance impact, autostart configuration, and filtering temp tables. Responses indicated minimal performance impact if selective row auditing is limited, autostart works via adtcfg.SERVERNUM file in $INFORMIXDIR/aaodir, and no built-in filtering exists for temp tables.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Performance & Tuning, Security, Permissions & Auditing
HI, I want to enable audit configuration on production database, before that need some advice/best practices to avoid any degrade performance on my production database. 1. When we enable audit, any impact to performance.? if yes, how to minimize this. 2. how to configure audit auto start with database, means when we start database with audit function enable. Any parameter on config file need to add to enable audit? 3. Can we customize output file for this audit? example when we allow audit to record "drop table",(DRTB) we want exclude TEMP table, no need to audit temp table. Please advice. Thank You
Hi, 1. In my experience there is very little measurable performance impact caused by auditing. I will caveat this by saying we don't use selective row auditing (not saying this is bad or slow, just we don't use it) and we don't audit select/insert/update/delete row much. Even if you do audit simple data changes the main consequence of this is huge audit files rather than poor performance. 2. Audit will auto-start if it is set up in the adtcfg or adtcfg.SERVERNUM file in $INFORMIXDIR/aaodir. This is documented in the Knowledge Centre: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.sec.doc/ids_au _107.htm 3. I don't know of any way to avoid auditing actions on temporary tables. I agree that this would be a useful feature. Ben.
Hi, Thank for your info. Based on this info, if we plan to set it as below: ADTMODE = 1 ADTERR = 0 ADTPATH = /mnt/informix/aaodir ADTSIZE = 20480000 Audit file = 0 ADTROWS = 1 How to set in on audit config file (adtcfg.servernumber)? Can u share samples adtcfg.servernumber file? If our audit file number 100, can we reset back to file number to 1? Please advice. Thank You
Answers inline On Thu, Sep 29, 2016 at 10:21 AM, MOHD FADZIL JUSOH <fadzil@isianpadu.com> wrote: > HI, > > I want to enable audit configuration on production database, before that > need > some advice/best practices to avoid any degrade performance on my > production > database. > > 1. When we enable audit, any impact to performance.? if yes, how to > minimize > this. > There isn't a simple answer to this. I hope you have some programming knowledge because that will help you understand my answer. When you activate auditing you define which operations will be udited for which users. The impact will be directly relted to the number of occurrences of operations that are to be audited. Let's think as a programmer, and plase notice I never saw Informix source code. But the auditing works more or less like this: When an auditable operation/function is executed it must do this; 1- Is auditing turned on? If yes, GOTO 2. If not continue with operation 2- Does the current session audit mask contain the bit for this operation? If yes continue to 3. If not continue with operation 3- Do the auditing 4- Operation Now... Test 1) is always done even if you don't have the auditing turned on. Test 2) is only done if auditing is turned on. This is an additional very, very fast test. Negligible impact Point 3) is what takes time... How many times does it happen? Depends on your auditing masks Let's try a more pragmatic approach... - GRANT/REVOKE operations... Should be audited. Do they happen many times? Probably not. - CREATE DROP TABLE. Should be audited. Do they happen many times? Probably not, unless your application creates a lot of temp tables - ROW level operations (read row, insert row, update row, delete row). Should be audited? Maybe... For which users? For which tables? These are the ones which happen more frequently... without cautious filters on users and/or tables it may kill the database performance. - EXECUTE PROCEDURE. Should they be audited? Maybe. Do they happen frequently? Depends on the application. I have a customer who executes around 200 procedures per second.... A final note on this. Some people need to audit all the operations from their DBAs to prevent unauthorized accesses. And yet, they are afraid that this may "kill" the performance. My point of view is this: If they shouldn't do the accesses, the operations will not happen, and the performance impact will not happen. The real question should be: Can they do their work without doing certain operations, and accessing sensitive data? It's not up to me to answer. > > 2. how to configure audit auto start with database, means when we start > database with audit function enable. Any parameter on config file need to > add > to enable audit? > The audit configuration will be stored in the system and within a file stored in $INFORMIXDIR/etc/aaodir (adtcfg.SERVERNUM) So after activating it you just nned to start/stop the instance as normal. > > 3. Can we customize output file for this audit? example when we allow > audit to > record "drop table",(DRTB) we want exclude TEMP table, no need to audit > temp > table. > We cannot prevent temp table creation/dropping from appearing in the audit files if we set CRTB and DRTB operations. I believe there was a RFE for that. Vote for it if you find it important. We cannot "customize" the audit files.... apart one environment variable that controls what appears in the client name (can show the client naem both as sent by the client and as seen by the server) I'm a bit tired of requesting the SID to be present in the audit files.... Without it, audit is nearly useless for JAVA applications as the client PID shows up as -1 (because pure AJva has no way to find it's PID). But with a PID of "-1" for all the operations/connections, we cannot understand the sequence of actions. There is also an RFE for this. > > Please advice. > > Thank You > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --94eb2c08e51882da9f053dff7fe3
Hello. Please use adtcfg.std as a baseline for your custom configs. You may copy it to adtcfg.SERVERNUM, according to your Informix onconfig SERVERNUM variable. For a complete help, please view the official Knowledge Center website. It is a very simple file. Just pay attention to audit masks you will enable, in order to avoid performance degradation. Hope this helps. Best regards. Alexandre Marini Em 3 de out de 2016 10:04 PM, MOHD FADZIL JUSOH <fadzil@isianpadu.com> escreveu: Hi, Thank for your info. Based on this info, if we plan to set it as below: ADTMODE = 1 ADTERR = 0 ADTPATH = /mnt/informix/aaodir ADTSIZE = 20480000 Audit file = 0 ADTROWS = 1 How to set in on audit config file (adtcfg.servernumber)? Can u share samples adtcfg.servernumber file? If our audit file number 100, can we reset back to file number to 1? Please advice. Thank You ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Hello. Informix native audit feature is a CPU intensive cost, only on the cases that Benjamin mention. Of course, If you have hundreds of users doing audit steps simultaneously, you should notice a performance degradation. If you intend to use a professional solution, fully integrated to Informix 12.10.xC6+ I would use the new Guardium utility, ifxguard. It can do professional stuff, ensuring your data and your server are secure. Hope this helps. Best regards. Alexandre Marini. Em 3 de out de 2016 9:32 PM, BENJAMIN THOMPSON <benjamin.thompson@skybettingandgaming.com> escreveu: Hi, 1. In my experience there is very little measurable performance impact caused by auditing. I will caveat this by saying we don't use selective row auditing (not saying this is bad or slow, just we don't use it) and we don't audit select/insert/update/delete row much. Even if you do audit simple data changes the main consequence of this is huge audit files rather than poor performance. 2. Audit will auto-start if it is set up in the adtcfg or adtcfg.SERVERNUM file in $INFORMIXDIR/aaodir. This is documented in the Knowledge Centre: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.sec.doc/ids_au _107.htm 3. I don't know of any way to avoid auditing actions on temporary tables. I agree that this would be a useful feature. Ben. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.