Fine Grain Auditing. 2004-06-18 - By Jonathan Lewis
For DDL the easiest option is to create database triggers:
create Or replace trigger before_drop
before drop
on test_user.schema
begin
raise_application_error(-20001, 'Dropping tables is naughty ');
end;
/
drop table t1;
drop table t1
*
ERROR at line 1:
ORA-00604 (See ORA-00604.ora-code.com): error occurred at recursive SQL level 1
ORA-20001 (See ORA-20001.ora-code.com): Dropping tables is naughty
ORA-06512 (See ORA-06512.ora-code.com): at line 2
Desc T1
Name Null? Type
-- ---- ---- ---- -- ----- -- ---- ----
N1 NUMBER
V1 VARCHAR2(10)
D1 DATE
It 's still there - but you could have use some of the
built-in functions for a more generic 'before DDL '
trigger to find out the command, object name, owner,
etc. and write the details into a log table using an
autonomous transaction.
The overheads of FGA are potentially disastrous,
and the exercise is probably a total waste of time.
Regards
Jonathan Lewis
http://www.jlcomp.demon.co.uk
http://www.jlcomp.demon.co.uk/faq/ind_faq.html
The Co-operative Oracle Users ' FAQ
http://www.jlcomp.demon.co.uk/seminar.html
Optimising Oracle Seminar - schedule updated May 1st
-- -- Original Message -- --
From: "Patamalla, Chaya " <chaya.patamalla@(protected) >
To: <oracle-l@(protected) >
Sent: Tuesday, June 15, 2004 7:58 PM
Subject: Fine Grain Auditing.
Has any one worked with Oracle 's Fine Grain Auditing.
What is the performance overhead.
Also, has anyone asked for auditing DDL? We are getting requirements
about auditing DDL functionality.
Thanks
Chaya Patamalla
I/T Sr.Database Administrator
-- "The opinions expressed herein are solely the author 's and are not
necessarily the opinion of USAA. " --
-- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ------
Please see the official ORACLE-L FAQ: http://www.orafaq.com
-- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ------
To unsubscribe send email to: oracle-l-request@(protected)
put 'unsubscribe ' in the subject line.
--
Archives are at http://www.freelists.org/archives/oracle-l/
FAQ is at http://www.freelists.org/help/fom-serve/cache/1.html
-- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- --
|
|