Activity Auditing Resources
An administrator in Oracle Cloud Infrastructure Identity and Access Management (IAM) can grant permissions as needed on the following Activity Auditing resources. As an alternative to selectively granting permissions, you can grant permissions on data-safe-audit-family
in the relevant compartments, which would include permissions on all of the resources below and target registration permissions.
data-safe-reports
Resource (see Common Resources)data-safe-report-definitions
Resource (see Common Resources)data-safe-work-requests
Resource (see Common Resources)
data-safe-audit-family Resource
The data-safe-audit-family
resource represents all Oracle Data Safe resources that pertain to Activity Auditing. The resources are as follows:
- data-safe Resource
- data-safe-private-endpoints Resource
- onprem-connectors Resource
- data-safe-work-requests Resource
- target-databases Resource
- data-safe-report-definitions Resource
- data-safe-reports Resource
- data-safe-audit-profiles Resource
- data-safe-audit-trails Resource
- data-safe-audit-events Resource
- data-safe-archive-retrievals Resource
- data-safe-audit-policies Resource
- data-safe-unified-audit-policies Resource
- data-safe-unified-audit-policy-definitions Resource
- data-safe-attribute-sets Resource
- data-safe-security-policies Resource
- data-safe-security-policy-configs Resource
- data-safe-security-policy-deployments Resource
The following table describes the permissions that you can assign to a group for the data-safe-audit-family
resource.
Permission | Description |
---|---|
inspect |
The user group can list all Activity Auditing resources in a specified compartment. |
read or use |
The user group can list and view properties for all Activity Auditing resources in a specified compartment. |
manage |
The user group can do the following:
|
data-safe-archive-retrievals Resource
The data-safe-archive-retrievals
resource represents
archive data retrieval objects in Activity Auditing.
The following table describes the permissions available for the
data-safe-archive-retrieval
resource.
Permission | Description |
---|---|
inspect |
The user group can list archive data retrievals. |
read or use |
The user group can list and view details for archive data retrievals. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) archive data retrievals. The group can also retrieve archive audit data and return it back to the archive. |
data-safe-audit-events Resource
The data-safe-audit-events
resource represents audit
events for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-events
resource.
Permission | Description |
---|---|
inspect |
The user group can list audit events. |
read |
The user group can list and view details for audit events. |
data-safe-audit-policies Resource
The data-safe-audit-policies
resource represents audit
policies for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-policies
resource.
Permission | Description |
---|---|
inspect |
The user group can list audit policies. |
read or use |
The user group can list and view details for audit policies. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) audit policies. |
data-safe-audit-profiles Resource
The data-safe-audit-profiles
resource represents audit
profiles for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-profiles
resource.
Permission | Description |
---|---|
inspect |
The user group can list audit profiles. |
read or use |
The user group can list and view details for audit profiles. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) audit profiles. A user can update the online and offline retention periods and paid usage setting. |
data-safe-audit-trails Resource
The data-safe-audit-trails
resource represents audit
trails for target databases in Activity Auditing.
The following table describes the permissions available for the
data-safe-audit-trails
resource.
Permission | Description |
---|---|
inspect |
The user group can list audit trails. |
read or use |
The user group can list and view details for audit trails. |
manage |
The user group can list, view details for, create, update, delete, and move (to another compartment) audit trails. |