Oracle 12C auditing for Splunk
Just one simple question to try to start with the best approach.
I intent to get my databases audited to deliver those OS files for Splunk, or share the directory. This is my idea.
What will be the best option?
- Create Splunk user for Splunk access directly to my database to UNIFIED_AUDIT_TRAIL view?
- No Splunk user, just a share directory with my save audit files. Internally, I'll export UNIFIED_AUDIT_TRAIL view into OS files. What will be the best approach with this scenario? AUDIT_TRAIL='OS'? The recommendations with this UNIFIED AUDIT option on 12C is to set AUDIT_TRAIL='NONE', so how to export that view to OS files? Dump?
Tagged:
0