Splunk Search

Oracle 12c UNIFIED_AUDIT_TRAIL to syslog server

paulopires16
Loves-to-Learn Lots

Dear community,

I have to implement Oracle 12c audit and save/export audit data to a shared drive on the SYSLOG server. Splunk will get the data for this SYSLOG server.

In a configuration like that, what is the best approach? Mixed auditing or Pure auditing?

My approach is to define pure audit and create 2 procedures:

  • Transfer UNIFIED_AUDIT_TRAIL to the SYSLOG server;
  • Clean up the auditing data from time to time.

With DBConnect, I must create a specific user, which I don't want.

Is there a step-by-step guide in windows to implement Oracle 12c auditing?

Thanks

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...