Database Security Products (MOSC)

MOSC Banner

How to configure unified audit with Dataguard and a SIEM tool

edited Feb 3, 2020 4:04AM in Database Security Products (MOSC) 2 commentsQuestion

I am looking for a recommendation on how to configure database auditing that will satisfy following:

1. All audit events must be replikated into a SIEM tool (in case: ArcSight)

2. No audit events must be lost.

3. Active Dataguard is used and audit trail management must be identical for primary and standby

4. Unified auditing is prefered

The issues I face are:

- SYSLOG has been demonstrated to drop events, when rate of events is high

- Database based audit trail does not include audit events on the standby database (audit logs are
written to filesystem)

- Binary audit log format is not compatible with ArcSight (not relevant for unified auditing)

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center