All Apps and Add-ons

Splunk Add-on for Oracle Database: database user shows as "/" or SYSDBA?

rfeldmann_sds
Loves-to-Learn Lots

Hello All,

 

Running Splunk v7, Splunk Add-on for Oracle Database v3.7.0, InfoSec App for Splunk 1.5.3. I was able to get a Universal Forwarder installed on a staging DB server and we now have the Audit logs flowing in and they seem to be getting parsed appropriately; i.e. fields look like they're being extracted correctly, etc.

 

The issue I seem to be running into is that we're not getting the individual users that are supposedly logging in, the database_user field shows up as just a slash, "/", or user is always SYSDBA. Can anyone who has this app setup and working well comment on how you got it setup to monitor authentications? We do want to track changes, as well, but we want to be able to watch login success and failure first.

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...