on-audit filtering via named pipe?
Posted in 2009
Topics: Security, Permissions & Auditing
All: on-audit only allows audit filtering by action (e.g. ACTB) and not by which table is involved. This makes it painful to use the native audit utility when you're only interested in auditing activity on a small handful of tables. I was wondering (haven't actually tried anything yet) if it would be possible to tell on-audit to write its audit logs to a named pipe that's feeding through grep? That way only the activities against the table of interest would get saved to the audit log file. I suspect this isn't possible, as the log file size management stuff and a comment I saw that "keeping an empty log file will prevent on-audit from reusing the file name" suggest that on-audit is too smart, would see the named pipe, and would pick a different filename to write to. Jonathan Leffler, any comment? :) -- John Hardin KA7OHZ Senior Applications Developer, BI Specialist EPICOR Retail web: http://www.epicor.com voice: (425) 245-1800 fax: (425) 670-1810 email: <jhardin@epicor.com> 20818 44th Ave. W., Suite 270 Lynnwood, WA 98036 USA Worldwide Headquarters 18200 Von Karman, Suite 1000, Irvine CA 92612 USA ------------------------------------------------------------------------ The first time I saw a bagpipe, I thought the player was torturing an octopus. I was amazed they could scream so loudly. ------------------------------------------------------------------------
It's not possible. The audit facility will write different files to a specified directory. You can parse each file as soon as it's completed, filtering what you need and then remove or archive the file. It's not that much different from what you were thinking. You just need some temporary file system space. Regards. On Fri, Sep 11, 2009 at 1:14 AM, John Hardin <jhardin@epicor.com> wrote: > All: > > on-audit only allows audit filtering by action (e.g. ACTB) and not by which > table is involved. This makes it painful to use the native audit utility > when you're only interested in auditing activity on a small handful of > tables. > > I was wondering (haven't actually tried anything yet) if it would be > possible to tell on-audit to write its audit logs to a named pipe that's > feeding through grep? That way only the activities against the table of > interest would get saved to the audit log file. > > I suspect this isn't possible, as the log file size management stuff and a > comment I saw that "keeping an empty log file will prevent on-audit from > reusing the file name" suggest that on-audit is too smart, would see the > named pipe, and would pick a different filename to write to. > > Jonathan Leffler, any comment? :) > > -- > John Hardin KA7OHZ > Senior Applications Developer, BI Specialist > EPICOR Retail > web: http://www.epicor.com > voice: (425) 245-1800 > fax: (425) 670-1810 > email: <jhardin@epicor.com> > 20818 44th Ave. W., Suite 270 > Lynnwood, WA 98036 USA > Worldwide Headquarters 18200 Von Karman, Suite 1000, Irvine CA 92612 USA > ------------------------------------------------------------------------ > The first time I saw a bagpipe, I thought the player was torturing an > octopus. I was amazed they could scream so loudly. > ------------------------------------------------------------------------ > > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Hi If you want to audit activity retrospectively (insert/deletes and updates) against tables please see www.lintel.co.uk/infotrace Very easy to use and works with the transaction logs. Regards David Linthwaite Lintel Software Consultancy Ltd IBM Business Partner Tel.: 01244 357250 Fax.: 01244 357248 mailto:dlinthwaite@lintel.co.uk -----Original Message----- From: informix-list-bounces@iiug.org [mailto:informix-list-bounces@iiug.org] On Behalf Of John Hardin Sent: 11 September 2009 01:15 To: informix-list@iiug.org Subject: on-audit filtering via named pipe? All: on-audit only allows audit filtering by action (e.g. ACTB) and not by which table is involved. This makes it painful to use the native audit utility when you're only interested in auditing activity on a small handful of tables. I was wondering (haven't actually tried anything yet) if it would be possible to tell on-audit to write its audit logs to a named pipe that's feeding through grep? That way only the activities against the table of interest would get saved to the audit log file. I suspect this isn't possible, as the log file size management stuff and a comment I saw that "keeping an empty log file will prevent on-audit from reusing the file name" suggest that on-audit is too smart, would see the named pipe, and would pick a different filename to write to. Jonathan Leffler, any comment? :) -- John Hardin KA7OHZ Senior Applications Developer, BI Specialist EPICOR Retail web: http://www.epicor.com voice: (425) 245-1800 fax: (425) 670-1810 email: <jhardin@epicor.com> 20818 44th Ave. W., Suite 270 Lynnwood, WA 98036 USA Worldwide Headquarters 18200 Von Karman, Suite 1000, Irvine CA 92612 USA ------------------------------------------------------------------------ The first time I saw a bagpipe, I thought the player was torturing an octopus. I was amazed they could scream so loudly. ------------------------------------------------------------------------ _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list