Informix Auditing
Posted in 2006
Topics: Security, Permissions & Auditing, Triggers, Constraints & Referential Integrity
Hello all, I have been reading about the auditing capabilities but no hands-on with it yet in a Development environment. Does anyone have experiences, good or bad, to comment on this feature? Is role separation required to be turned on? I ran into an article some time ago concerning "Fine Grained Auditing" from IBM that allows us to write a generic trigger function that can record the changes made to any table in the database. I am not sure how it would compare to the built-in feature and how they compare in overhead. Any posts are appreciated! Thanks, Tom
Onaudit is a HOG. You can expect a 40% - 60% performance decrease. Even if you only turn it on and don't have any masks. You do not need role separation if you trust your DBA. Overall there should be a separate security person to manage the auditing. The "Fine Grained Auditing" is very useful and there are several presentations and papers about this topic. It was presented at the last couple of conferences and you can search www.ibm.com for the white paper. Jacques Roy is the SME for Fine Grained Auditing. Just search iiug.org or ibm.com for anything he has published. GO FURTHER...with Informix IDUG 2006 North America, May 7-11, 2006, Tampa, Florida, USA Visit www.iiug.org/conf for the latest conference information