Create and Manage Subsetting Policies
On the Subsetting policies page, you can view the list of subsetting policies in a compartment, create a new subsetting policy, and upload a subsetting policy.
Create a Subsetting Policy for a Target Database
When you create a subsetting policy for a target database, you work through the following parts:
- Part A: Specify policy details and schema source
- Part B: Verify the relationship graph based on the selected schemas
- Part C: Add application-level referential relationships (available if your source is a schema)
- Part D: Create subsetting rules
Part A: Specify Policy Details and Schema Source
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
The Subsetting policies page shows a list of all subsetting policies in the selected compartment.
-
Select Create subsetting policy.
The Create subsetting policy panel opens.
-
Under Subsetting policy details, do the following:
a. Accept the default subsetting policy name or enter a new one.
b. (Optional) Enter a description for the subsetting policy.
c. Select a compartment to store the subsetting policy.
-
Under Policy source details, do the following:
a. From the dropdown lists, select a database compartment and a target database name.
b. Under Select policy source, select Get schemas from sensitive data model or Select schemas.
c. If the source is a sensitive data model (SDM), select the sensitive data model’s compartment and name.
d. If the source is schemas, select Select specific schemas or All schemas. For the first option, select the check boxes for the specific schemas that you want to use. Search for schemas if needed. Select Refresh database schemas if needed.
-
Under Tags, add tags for the subsetting policy resource as needed.
-
Select Create subsetting policy and wait for the subsetting policy to be created.
You are directed to the Details page of the subsetting policy.
Part B: Verify the Relationship Graph Based on the Selected Schemas
-
On a subsetting policy page, select the Referential relationships tab.
-
Select View relationship graph.
A Relationship graph panel opens.
-
Search and filter as needed.
-
(Optional) Select Legend to view the legend for the graph.
-
To move the graph, select the white space, and then drag it.
-
To view information about a table, select it. A panel opens showing the schema and table name, and when the table was created and updated. Select X to close the panel.
-
To alter the view, select the Fit to canvas, Refresh canvas data, Zoom in or Zoom out button.
-
Select the browser back button to return to the subsetting policy.
Part C: Add Application-Level Referential Relationships
If the subsetting policy source consists of schemas directly from the target database, then you have the option to add an application level relationship. If the source is a sensitive data model (SDM), it already has application level relationship information and therefore, the option to add relationships here is not available.
Database referential relationships are automatically discovered for a subsetting policy.
-
On a subsetting policy page, select the Referential relationships tab.
-
Select Add application level relationship.
The Add application level relationship panel opens.
-
If needed, select Refresh database schemas.
-
Select a parent schema name and parent table name.
-
Select a child schema name and child table name.
-
Select a parent column name and child column name.
-
(Optional) If multiple columns are involved in the relationship, select Add composite relation, and then select another parent column name and child column name. You can add more columns this way as needed.
-
Select Add application level relationship.
-
To remove an application level relationship, select the three dots on its row, select Remove relationship, and confirm the removal.
Database referential relationships cannot be removed.
Part D: Create Subsetting Rules
A subsetting policy needs to be associated with a rule. The recommended options for ancestors, descendants and other related tables are selected by default.
-
On a subsetting policy page, select the Subsetting rules tab.
-
To add a subsetting rule, select Add subsetting rule.
The Add driving tables panel opens. The table lists the available driving tables. Each row has the following information:
- Schema name for the table
- Table name
- Size of the table
- Number of rows in the table
- Number of ancestors and descendants
- Role (The role shows when you select a driving table.)
-
Search and filter as needed.
-
Select a driving table.
- The rule will be configured around the driving table.
- When you select a driving table, the Role column shows the relationships with the other tables (for example, Ancestor, Descendant).
-
Select Next.
The Define rule panel opens.
-
Review the schema(s), driving table, ancestors, and descendants.
- To view ancestors or descendants, select their respective View button.
-
(Optional) To view the relationship graph, select View relationship graph.
A Relationship graph panel opens.
Search and filter as needed. Optionally, select Legend to view the legend for the graph. Select Close when finished.
-
Under Select rule type, select one of the following options:
-
Percentage - Enter a percentage value in the Percentage of rows to retain box.
-
Condition - Select a Column name, select an Operator, and enter a Value. Select Add another condition if needed. Alternatively, select Show manual editor, and enter a condition manually in the box.
-
Condition and percentage - Configure both a condition and percentage. First, the rows matching the condition are retained. Then, a percentage of those rows are retained.
-
-
Under Ancestors, select one of these options:
- Keep only referenced rows to keep only ancestor rows referenced by the driving table
- Keep all rows to keep every row in the ancestor tables
-
Under Descendants, select one of these options:
- Keep only referencing rows to keep only descendant rows that reference retained rows in the driving table
- Remove all rows to remove every row from the descendant tables
-
Under Other related tables, select one of these options:
- Keep maximum rows to keep as many rows as possible in related tables while ensuring that all references to the retained driving table rows remain valid
- Propagate the subset rule to keep only rows in other related tables that are related to the retained rows in the driving table
- Keep minimum rows to retain rows required to maintain referential integrity
-
Select Next.
The Review and add panel opens.
-
Review the configuration and the relationship graph.
-
Select Add.
After the rule is added, you can view the processing chain and other details about the subsetting rule.
View Table Estimates
Table estimates need to be calculated at least once to be listed.
-
With a subsetting policy open, select the Table estimates tab.
-
To calculate or refresh table estimates, do the following:
a. Select Calculate estimates. The Calculate estimates dialog box appears.
b. Enter your database username and password, and select Calculate estimates. Wait until the processing is completed and the Table estimates page is displayed.
c. For each table listed, review the following information:
- Initial row count
- Estimated row contribution
- Original size
- Estimated size contribution
- Size reduced by
-
(Optional) To calculate estimates using the same policy on a different target database, do the following:
a. Select Change database. A Change database dialog box appears.
b. Select the database compartment and database name.
c. Select Update.
Rename a Subsetting Policy
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Search and filter as needed.
-
Select the name of the subsetting policy that you want to rename.
The Subsetting policy page opens.
-
From the Actions menu, select Edit display name.
The Edit display name panel opens.
-
Enter a new name for the subsetting policy, and then select Update.
Update the Description for a Subsetting Policy
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Search and filter as needed.
-
Select the name of the subsetting policy whose description you want to update.
The Subsetting policy page opens.
-
From the Actions menu, select Edit description.
The Edit description panel opens.
-
Modify the description for the subsetting policy, and then select Update.
Edit the Subsetting Policy Scope
-
On the Details tab for a subsetting policy, under Policy scope, select Edit policy scope.
The Edit policy scope panel opens.
-
Change the target database, sensitive data model, or schemas used by the subsetting policy.
-
Select Update.
Configure or Edit a Masking Policy in a Subsetting Policy
-
On the Details tab for a subsetting policy, under Masking policy, select Enable or Edit.
The Edit masking policy panel opens.
-
In the dropdown lists, select a masking policy compartment and masking policy name.
-
Select Update.
Edit Subsetting Options for a Subsetting Policy
-
Navigate to the Details tab for a subsetting policy.
-
From the Actions menu, select Edit subsetting options.
The Edit subsetting options panel opens.
-
Edit options for unrelated tables, parallel execution, redo log generation, recompiling invalid objects, and refreshing statistics after subsetting.
-
Select Update.
Upload Pre and Post Subsetting Scripts
-
Navigate to the Details tab for a subsetting policy.
-
From the Actions menu, select Upload scripts.
The Upload scripts panel opens.
-
Drop a file or select one for the pre and post subsetting script options.
-
Select Submit.
Generate an XML Policy
You can generate a downloadable XML file corresponding to a subsetting policy. It can be used for offline review and editing.
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Search and filter as needed.
-
Select the name of the subsetting policy that you want to generate as an XML file.
The Subsetting policy page opens.
-
From the Actions menu, select Generate policy.
The Generate subsetting policy dialog box appears.
-
Select Generate policy.
-
Select Download policy to download the XML file to your browser.
-
Select Close.
Download an XML Policy
Use this option to download an already generated XML file corresponding to the selected subsetting policy. It can be used for offline review and editing.
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Search and filter as needed.
-
Select the name of the subsetting policy that you want to download as an XML file.
The Subsetting policy page opens.
-
From the Actions menu, select Download policy.
The Download subsetting policy dialog box appears.
-
Select Download policy.
The subsetting policy is downloaded to the browser.
Upload a Subsetting Policy
You can use XML file content to create a new subsetting policy or update an existing policy.
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Select Upload subsetting policy.
The Upload subsetting policy panel opens.
-
Select Create a new subsetting policy or Update an existing subsetting policy.
-
If you are creating a subsetting policy, do the following:
a. Enter a subsetting policy name.
b. Enter a description for the subsetting policy.
c. Select a compartment to store the subsetting policy.
d. To upload a subsetting policy and associate it with a selected database, select Using a database. Select the database compartment and database name.
e. To automatically retrieve schema and application level relationship information from a sensitive data model, select Using a sensitive data model. Select the SDM’s compartment and name.
-
Select a subsetting policy file (XML file only).
-
(Optional) Expand Tags, and add additional metadata to resources with free-form and defined tags.
-
Select Upload subsetting policy.
Move a Subsetting Policy
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Search and filter as needed.
-
Select the name of the subsetting policy that you want to move.
The Subsetting policy page opens.
-
From the Actions menu, select Move resource.
The Move resource dialog box appears.
-
Select a compartment, and then select Move resource.
The subsetting policy is moved immediately.
Delete a Subsetting Policy
-
Under Data Safe - Database Security, expand Data subsetting, and then select Subsetting policies.
-
Search and filter as needed.
-
On the row for the subsetting policy that you want to delete, select the three dots, and then select Delete.
The Delete dialog box appears.
-
If you are sure that you want to delete your subsetting policy, select Delete.
The subsetting policy is deleted immediately.