public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Cc: Mathew Brown <mathewbrown@fastmail.fm>
Subject: Re: Using Linux Audit to Audit / Log All Oracle Related Activity
Date: Mon, 17 Dec 2007 08:36:39 -0500	[thread overview]
Message-ID: <200712170836.39984.sgrubb@redhat.com> (raw)
In-Reply-To: <1197897678.9239.1226981649@webmail.messagingengine.com>

On Monday 17 December 2007 08:21:18 Mathew Brown wrote:
> I was wondering if the Linux Audit Daemon could be used to address the
>   issue of Oracle auditing.  Has anyone investigated this possibility?

What would you like to know about Oracle?

>   Ideally, I would like to audit all network (listener) as well as all
>   local access (an Oracle DBA running sqlplus directly on the machine).

You mean accepting the connection? I think you can get all accepts that Oracle 
would issue, but I don't know if you will get the remote address in the logs. 
You also cannot tell it that you want accepts of a specific socket.

You might want to spend some time looking at Oracle from strace. That is about 
the view of the world from the Linux Audit System. If you can't find anything 
worth logging from that, it most likely means that you'd want Oracle to be 
patched to send meaningful events to the audit system.

-Steve

  reply	other threads:[~2007-12-17 13:36 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-12-17 13:21 Using Linux Audit to Audit / Log All Oracle Related Activity Mathew Brown
2007-12-17 13:36 ` Steve Grubb [this message]
2007-12-22 15:06   ` Mathew Brown

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200712170836.39984.sgrubb@redhat.com \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    --cc=mathewbrown@fastmail.fm \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox