Re: ONAUDIT or trigger & st.or. procedure
Posted in 2004
Topics: Stored Procedures & SPL, Security, Permissions & Auditing, Triggers, Constraints & Referential Integrity
>Problem with onaudit utility is that its output is not "human
readable" .
I'd revisit the manuals again. So what can read theoutput if a human
can't? otherwise how would the "auditor" read it. I see to recall
there is a tool to load the onaudit output into a specific database
table so you can run queries against it. If a human can't read the
onaudit output, what would be the purpose of the tool.
>and it can't work on table level
Hmm, again, I'd suggest you revisit the manual!! Its been a while
since I used onaudit, however I seem to recall you can select the
indiviual tables you want to audit, and the activities on those tables
that you want to audit eg only inserts and even on failed inserts
Nebojsa Sevo <DELETE_mips@zg.tel.hr> wrote in message news:<r17r309s3698jr53p2p9vcspc42rhgmd6r@4ax.com>...
> My customer have request to monitor update / delete activities on some tables. I
> read Trusted Facility Manual. Problem with onaudit utility is that its output is
> not "human readable" and it can't work on table level.
> I know how to get table name from tabid and how to get data from rowid but I am
> not sure that it is right way.
> If I will use triggers and stored procedures problem is that I have to change
> them every time I change table definition.
> If anybody has experience with "monitoring DB activity" or suggestions, please
> share it with me.
>
> Thanks in advance
>
> Nebojsa
> ------------------------------------
> Remove spam block (DELETE_) to reply
Thanks for your suggestions. I read manual again and didn't find what are you
suggesting. Maybe I don't know to explain what is the problem.
>I'd revisit the manuals again. So what can read theoutput if a human
>can't? otherwise how would the "auditor" read it. I see to recall
>there is a tool to load the onaudit output into a specific database
>table so you can run queries against it. If a human can't read the
>onaudit output, what would be the purpose of the tool.
>
"Human readable" output, for me, will be output that has "table name" instead
"tabid" (not a big problem) and instead "rowid" has values for unique key
fields, at least.
What can you do with "rowid" of deleted record???
>>and it can't work on table level
>
>Hmm, again, I'd suggest you revisit the manual!! Its been a while
>since I used onaudit, however I seem to recall you can select the
>indiviual tables you want to audit, and the activities on those tables
>that you want to audit eg only inserts and even on failed inserts
I can't find how can I put audit mask for individual tables. I can put masks for
events and users.
I will be very nice of you if you tell how to put mask (in onaudit
configuration, not in onshowaudit) on tables.
Nebojsa
------------------------------------
Remove spam block (DELETE_) to reply
OK, now I have my manuals to hand, appendicx G of my Server admin
training manual says
"The onshowaudit utility is used to view audit events can only be run
by the AA0. The onaudit utility can only be used by the DBSSO to
maintain audit masks"
Nothing to stop the AAO and the DBSSO being the same person!!
onshowaudit -f <audit-file> -l -u <login> -s <server_name>
I agree I don't find any mention of "only audit thses tables", sorry.
dryburghj@yahoo.com (scottishpoet) wrote in message news:<81714288.0402261159.35b2eb1e@posting.google.com>...
> >Problem with onaudit utility is that its output is not "human
> readable" .
> I'd revisit the manuals again. So what can read theoutput if a human
> can't? otherwise how would the "auditor" read it. I see to recall
> there is a tool to load the onaudit output into a specific database
> table so you can run queries against it. If a human can't read the
> onaudit output, what would be the purpose of the tool.
>
> >and it can't work on table level
>
> Hmm, again, I'd suggest you revisit the manual!! Its been a while
> since I used onaudit, however I seem to recall you can select the
> indiviual tables you want to audit, and the activities on those tables
> that you want to audit eg only inserts and even on failed inserts
>
>
> Nebojsa Sevo <DELETE_mips@zg.tel.hr> wrote in message news:<r17r309s3698jr53p2p9vcspc42rhgmd6r@4ax.com>...
> > My customer have request to monitor update / delete activities on some tables. I
> > read Trusted Facility Manual. Problem with onaudit utility is that its output is
> > not "human readable" and it can't work on table level.
> > I know how to get table name from tabid and how to get data from rowid but I am
> > not sure that it is right way.
> > If I will use triggers and stored procedures problem is that I have to change
> > them every time I change table definition.
> > If anybody has experience with "monitoring DB activity" or suggestions, please
> > share it with me.
> >
> > Thanks in advance
> >
> > Nebojsa
> > ------------------------------------
> > Remove spam block (DELETE_) to reply