Unified auditing and centralized logging solution (SPLUNK)

In this part, we will see one way of sending unified auditing data to a centralized logging solution outside the Oracle Database. We will not be looking at remote SYSLOG as there is many missing information when redirecting audit data to syslog (Missing Audit Infomation In The Unified Audit Trail Records Sent To SYSLOG (Doc ID 2520613.1))

Still for remote syslog auditing we can set the parameter “unified_audit_systemlog= ‘LOCAL5.INFO’”

In addition, add the following entry in “rsyslog.conf” to enabled Reliable Message forwarding (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system_administrators_guide/s1-working_with_queues_in_rsyslog) :

Capture syslog remote

On the remote audit server just uncomment the lines “$ModLoad imtcp $InputTCPServerRun 514”.

Ok but this is not the purpose of this blog post, here we are going to look at how we can integrate oracle unified audit data with SPLUNK using Splunk DB Connect and the oracle add-on.

Capture splunk

We first start by installing SPLUNK in our test server.

Capture 1

The second step will be to add two new applications:

  • Splunk DB Connect
  • Splunk Add-on for Oracle Database

capture app

Configure the JAVA environment parameters and add the oracle driver.

Capture JAVA

Configure a new Identity and then add a new connection for our target database (oracle 19C instance with unified auditing enabled) :

Capture identity and connc

Configure a new data INPUT with the “oracle:audit:unified” Template :

Capture data input

Capture data input 2

That’s it we can now query our auditing data an build custom dashboard and reports :

capture r1

capture r4capture r3capture r2

That’s it 🙂

REF :

 

 

 

 

 

 

 

 

One thought on “Unified auditing and centralized logging solution (SPLUNK)

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s