Splunk Search

How should we handle DB audit trails?

danielbb
Motivator

We would like to ingest the Oracle's UNIFIED_AUDIT_TRAIL table and the SQL server's MSSQL\SQLAudit\*.sqlaudit files.

How should we do it? Should we index the Oracle's UNIFIED_AUDIT_TRAIL table? Is there maybe an add-on? And what should we do on the SQL Server side? Should we read the files themselves?

Labels (1)
Tags (2)
0 Karma

altink
Builder

For Oracle Unified Audit (starting with Oracle 12c R1), you can use the following

Oracle Unified Audit App for Splunk

https://splunkbase.splunk.com/app/6172/ 

best regards
Altin

0 Karma

danielbb
Motivator

We also wonder whether the Windows event logs have information about the SQL Server audit information.

A good conversation about the Oracle audit trails at - https://community.splunk.com/t5/Splunk-Search/How-to-index-Oracle-audit-trails-stored-in-aud-files/m... 

 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...