Preparation for audit analysis

This section describes two methods to analyze database server audit records:

Important: The SQL-based procedure is more convenient but remains untrusted because users can use SQL data-manipulation statements to tamper with the records that are copied into a table.

Both methods rely on a utility called onshowaudit, which Audit analysis and The onaudit utility: Configure audit masks describe. For either method, you can extract audit events for specific users, database servers, or both.

To perform audit analysis, first have audit records in your database server. The onshowaudit utility does not remove data from the audit trail. It only reads records from the audit trail and allows them to be viewed or manipulated with standard SQL utilities.

To clear or remove audit logs, delete the files that contain the audit trail.


Copyright© 2020 HCL Technologies Limited