Configuring DSMs
51
O
RACLE
This section provides information on configuring the following DSMs:
•
Oracle Audit Records
•
Oracle DB Listener
•
Oracle Audit Vault
•
Oracle OS Audit
•
Oracle BEA WebLogic
Oracle Audit
Records
Oracle databases track auditing events, such as, user login and logouts,
permission changes, table creation, and deletion and database inserts. SIEM can
collect these events for correlation and reporting purposes through the use of the
Oracle Audit DSM. For more information, see your Oracle documentation.
NOTE
Oracle provides two modes of audit logs. SIEM does not support fine grained
auditing.
Oracle RDBMS is supported on Linux only when using syslog. Microsoft Windows
hosts and Linux are supported when using JDBC to view database audit tables.
When using a Microsoft Windows host, verify database audit tables are enabled.
These procedures should be considered guidelines only. We recommend that you
have experience with Oracle DBA before performing the procedures in this
document. For more information, see your vendor documentation.
Before SIEM can collect Oracle Audit events from an Oracle RDBMS instance, that
instance must be configured to write audit records to either syslog or the database
audit tables. For complete details and instructions for configuring auditing, see
your vendor documentation.
NOTE
Not all versions of Oracle can send audit events using syslog. Oracle v9i and 10g
Release 1 can only send audit events to the database. Oracle v10g Release 2
and Oracle v11g can write audit events to the database or to syslog. If you are
using v10g Release 1 or v9i, you must use JDBC-based events. If you are using
Oracle v10g Release 2, you may use syslog or JDBC-based events.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......