Auditing?
Posted in 2019
Topics: Security, Permissions & Auditing
IDS 12.10.FC12
Solaris 10 1/13
In the past, we have not been very concerned about auditing. But, things are
changing, and it seems that some managers now want to "take it to the limit",
auditing-wise.
Having poked at onaudit briefly, several months ago, I have limited experience
with it.
I wonder if configuring a separate machine as an RSS to the Production server,
and absolutely LOADED with TBs of storage, just might be a way to "audit
everything" (which is the way the objective was stated to me) without
affecting resources on the production server.
Does that make any kind of sense?
Or maybe for real flexibility, Guardium is more appropriate. But, again, does
it make sense to offload that mission to an RSS?
Comments gladly welcomed. I really do not know much about auditing.
Apparently, some federal requirements have magically appeared in recent years
(and more likely on way) for the kind of work we do, and the data we store.
And our agency is now getting serious about it.
Thank you.
DG
Original post:
IDS 12.10.FC12
Solaris 10 1/13
In the past, we have not been very concerned about auditing. But, things are
changing, and it seems that some managers now want to "take it to the limit",
auditing-wise.
Having poked at onaudit briefly, several months ago, I have limited experience
with it.
I wonder if configuring a separate machine as an RSS to the Production server,
and absolutely LOADED with TBs of storage, just might be a way to "audit
everything" (which is the way the objective was stated to me) without
affecting resources on the production server.
Does that make any kind of sense?
Or maybe for real flexibility, Guardium is more appropriate. But, again, does
it make sense to offload that mission to an RSS?
Comments gladly welcomed. I really do not know much about auditing.
Apparently, some federal requirements have magically appeared in recent years
(and more likely on way) for the kind of work we do, and the data we store.
And our agency is now getting serious about it.
Thank you.
DG
Response:
I don't think this is going to work. I believe you can audit database access
(so just connecting), this will not show up on the RSS node for a user doing
work on the primary. You can audit selects, this will also not show up on the
RSS node (for selects done on the primary). I'm not 100% sure on this, I'd
have to look at code, which I can't do at this moment, but I believe the
auditing happens at what I'll describe as a higher level, then say where log
records are generated and applied, so if you inserted a row on the primary, I
do not think if that insert was applied on the RSS node that you would hit the
audit code. I know nothing about Guardium, but I don't think you could use
Guardium to "audit" your RSS node and have it pick up stuff happening on the
primary either. I can confirm the Informix auditing part later, but if my
memory of how the auditing is happening, I do not believe you will be able to
offload the auditing of the primary to a RSS node (I can say for certain that
things like database connections and selects which can be audited have no way
of showing up on an RSS node since all it's doing is applying log records
generated on the primary).
Jacques Renaut
HCL Informix Advanced Support
Thank you, so much, Jacques. I appreciate your comments. I was definitely on the wrong track. I should have thought of the inability to audit on the secondary, events that are not logged on the primary. But, I could NOT know that "auditing happens at what I'll describe as a higher level, then say where log records are generated and applied." So, your information was very helpful. You helped us avoid a time-consuming and expensive bunny trail. Thank you. Regards, DG