Installing and Enabling the Host Monitor Agent
Use this process to install and enable the Host Monitor Agent.
-
Deploy the Host Monitor Agent on all the database servers where the database is running.
-
Register the target.
-
Create a Database Firewall monitoring point in Monitoring (Host Monitor) mode.
-
Change the Database Firewall policy for the target from Default to the appropriate policy, if needed.
See Types of Database Firewall Policies for the different policy types.
-
Configure a
NETWORKaudit trail for the monitored target.Note:
-
The Host Monitor Agent is supported on Linux, Solaris, AIX, and Windows platforms. It can monitor any database that is supported by the Database Firewall. See Table C-1 for supported databases.
-
The Host Monitor Agent supports the Solaris IPNET link type on Oracle Solaris SPARC64 and x86-64.
-
The Host Monitor Agent supports the Ethernet (EN10MB) link type for all supported platforms.
-
The Host Monitoring Agent can inspect SQL commands issued using local connections to the database through loopback (non-Oracle and Oracle) and bequeath (Oracle) when the Database Firewall is deployed in Monitoring (Host Monitor) mode. With this feature, the Host Monitoring Agent has complete visibility into database activities performed by all users including administrators accessing the database server as such. For a comprehensive visibility, it is recommended to augment network monitoring with database auditing. Database auditing running inside the Oracle Database has complete visibility into the internal jobs or procedure execution which typically network monitoring might not have access to. Database auditing cannot be bypassed by the use of synonyms or dynamically generated names, while network monitoring policies should be trained for all such possible combinations to make it foolproof.
-
Related Topics
Host Monitor Agent Requirements
The Host Monitor Agent has different requirements for installation, depending on the platform.
To install the Host Monitor Agent on the Windows platform, follow these requirements:
-
Ensure that the Audit Vault Agent is running on the database server machine.
-
Follow the Npcap installation requirements for your Oracle Database Security Central (Oracle DBSecCentral) release.
Host Monitoring on Windows requires Npcap for capturing network traffic.
-
Npcap is automatically installed along with the agent installation.
Installing Npcap removes any existing installation of Npcap or WinPcap from the Windows host machine.
-
-
Ensure that the Windows target machine has the latest update of the Visual C++ Redistributable for Visual Studio 2015 (
MSVCRT.dll (*)or later) package from Microsoft installed. -
If a network firewall is present, allow communication on port range 2050 - 5200. This is required for communication between the database server and the Database Firewall.
Allowing communication on port 7447 is necessary for the Audit Vault Agent to connect to the Audit Vault Server.
To install the Host Monitor Agent on a Linux, Unix, AIX, or Solaris platform, follow these requirements:
-
Ensure that the Audit Vault Agent is running on the database server machine.
-
Ensure that the latest version of the following packages from the operating system vendor are installed for the specific operating system version on the database server machine:
-
Libcap (for Linux hosts only)
-
LibPcap
-
-
Ensure that
gmakeis installed for AIX database servers.For other Unix database server types (Linux, Unix, or Solaris), ensure that
makeis installed. This is required for the Host Monitor Agent to run successfully. -
If a network firewall is present, allow communication on port range 2050 - 5200. This is required for communication between the database server and the Database Firewall.
Allowing communication on port 7447 is necessary for the Audit Vault Agent to connect to the Audit Vault Server.
-
Ensure that the input output completion ports (IOCP) setting is
availablefor IBM AIX on Power Systems (64-bit).It’s set to
definedby default. -
Ensure that all directories in the path of the Host Monitor Agent install location have 755 as the permission bits, starting from the root directory.
This is required because the Host Monitor Agent has to be installed in a root-owned location.
-
Ensure that the Host Monitor Agent is installed by the root user.
Related Topics
See Also: Enabling and Using Host Monitoring for host monitoring instructions and prerequisites.
Validation During Host Monitor Agent Deployment
Learn about validations performed by Oracle Oracle Database Security Central when deploying the Host Monitor Agent.
The following validations are performed on the Linux/Unix/AIX/Solaris platforms when deploying the Host Monitor Agent. These requirements are mandatory and must be complied with; without meeting them, the Host Monitor Agent installation cannot be completed.
-
The Host Monitor Agent is being installed as root user.
-
When installing the Host Monitor Agent on a Windows platform, it must be installed by an administrator user.
-
If Host Monitor Agent process is already running on the host machine.
-
If the Input Output Completion Ports (IOCP) is set to
availablefor IBM AIX on Power Systems (64-bit). -
If gmake is installed for AIX database servers. For other Unix database server types (Linux/Unix/Solaris), check if make is installed.
-
If symlinks of the
libnsllibrary are present. In case of Linux, a check for additional symlinklibaiois performed.Note:
If you run into any issues, see the following topics for more information:
Registering the Host Machine That Will Run the Host Monitor Agent
Learn how to register the host machine (such as a database server) on the Audit Vault Server.
To register a host on the Audit Vault Server, see Registering Hosts on the Audit Vault Server.
Deploying the Audit Vault Agent and Host Monitor Agent
Learn how to deploy the Audit Vault Agent and Host Monitor Agent on platforms like Linux, Solaris (x86-64), Solaris (Sparc64), AIX, and Windows.
Deploying the Host Monitor Agent on a Windows Host Machine
On Windows, the Host Monitor Agent is installed by the Audit Vault Agent. There are no separate Host Monitor Agent installable bundles available for download in the Oracle Database Security Central console. No separate action is required to install the Host Monitor Agent on Windows.
Follow these instructions before installing the Host Monitor Agent or updating from an older Oracle DBSecCentral release.
Prerequisites
Related Topics
Deploying the Host Monitor Agent on a Unix Host Machine
Learn about deploying the Host Monitor Agent on Unix hosts.
Prerequisite Host Monitor Agent Requirements
-
Before you install the Host Monitor Agent, ensure you have deployed the Audit Vault Agent.
-
Log in as
rootand identify aroot-owned directory on the local hard disk, such as/usr/local, where you will install the Host Monitor Agent.Note: The entire directory hierarchy must be
root-owned. All the directories in this hierarchy must havereadandexecutepermission for other users or groups, but notwritepermission. -
Log in to the Oracle Database Security Central console as an administrator.
-
Select Agents.
-
In the left navigation menu, Select Downloads.
-
On the page listing the agent software, select Download button corresponding to your Unix version, and then save the
.zipfile to theroot-owned directory (on the local hard disk) you identified in Step 2, for example/usr/local. -
As
rootuser, unzip the Host Monitor Agent file,agent-<platform>-hmon-one.zip(for example,agent-linux-x86-64-hmon-one.zip).This creates a directory named
hm. This is your HM_Home directory, which in this example is/usr/local/hm. -
Ensure that the
hostmonsetupfile (in thehmdirectory) has the execute permission for the owner. -
Run the following command from the
HM_Homedirectory:<HM_Home>/hostmonsetup install [agentuser=<Agent_Username>] [agentgroup=<Agent_Group>]-
HM_Home - The directory created in Step 7.
-
Agent_Username - (Optional) Enter the user name of the user who installed the Audit Vault Agent (the user who executed the
java -jar agent.jarcommand). -
Agent_Group - (Optional) Enter the group to which the Agent_Username belongs.
-
Creating a Target for the Host-Monitored Database
Learn how to create a target for the host-monitored database.
To create a target, see Registering or Removing Targets in Audit Vault Server.
Creating a Monitoring Point for the Host Monitor Agent
A monitoring point is a logical entity on the Database Firewall host that contains the configuration and rules for monitoring the SQL traffic that is received.
-
Log in to the Oracle Database Security Central console as an administrator.
-
Select Targets. The Targets in the left navigation menu is selected by default.
-
Select and select a specific target from the list.
-
From the Database Firewall Monitoring section on the main page, select Add. The Database Firewall Monitor dialog is displayed.
-
In the Core, enter the name for the Database Firewall instance or select one from the list.
-
Select Monitoring (Host Monitor) as the deployment type from the list. In this mode, the Database Firewall can only monitor the SQL traffic.
-
Choose a Network Interface Card for the Database Firewall host from the list.
Note: You must select a network interface card which has an IP address configured. All the network interface cards which have an IP address configured are displayed in the Network Interface Card list. It is recommended to select a network interface card that is not used as a Management Interface. This segregates the traffic from Host Monitor Agent to the Database Firewall and the traffic from the Database Firewall to Audit Vault Server.
-
In the Connection Details section, select one or more targets for which the traffic needs to be monitored. You can Add the targets from the list.
Note:
-
For Exadata or Oracle RAC, enter both the physical and virtual IP’s of the nodes but not the SCAN IPs in the Target Connections field.
-
For Oracle RAC, enter the IP address of the individual RAC node in the Target Connections field.
Enter the following information for each available connection of the database. Select Add to add more targets and enter the following fields:
-
Host Name / IP Address
-
Port
-
Service Name (Optional, for Oracle Database only). SID can be used in this field. To enter multiple service names and/or SIDs, enter a new line for each of them, and then select Add. Multiple entries are allowed for monitoring only mode.
- You can use one proxy port and specify multiple OSNs on the target database that are going to be processed. Specify the OSNs in a list delimited by the “" character. For example, target1\target2\target 3.
Note: For Linux hosts with multiple network devices, add a row for every network device from which the database traffic is expected to arrive.
-
-
Select Advanced, enter the number of Database Firewall Monitor Threads (minimum value is 1). This controls the number of traffic handling threads in the Database Firewall monitoring point. The default value is 1. This value can be increased when high transactions are reported (per second traffic) and packet dropped messages are reported in the
/var/log/messagesfile. Contact Oracle Support while changing this number. -
Select the checkbox for Decrypt With Network Native Encryption Key field only for Oracle Database targets. This is for enabling decryption of traffic if the database is using Oracle Native encryption. Decrypt with network native encryption key option also supports retrieval of session information for Oracle Database. Complete the remaining fields as applicable.
For Oracle standalone database targets, enter the IP address of the database listener in the IP Address field.
For Microsoft SQL databases, the field is Retrieve session information from target DB. Retrieving session information is not available for any other non-Oracle database types.
Select this field to retrieve session information such as OS User Name, DB User Name, client application name, and IP address from the target database.
Note: Ensure the Database Firewall is allowed to make a network connection to the above mentioned database.
-
Select Save at the bottom of the dialog to save the configuration of the monitoring point.
The new monitoring point appears in the list and starts automatically.
Note:
Default Database Firewall Policy will be applied for this Database Firewall Monitoring Point. This message is displayed at the bottom of the dialog. -
Select Save in the main page.
-
To stop or restart the monitoring point, select it from the Database Firewall Monitoring section and select Stop or Start.
Create a Network Audit Trail
Learn how to create network audit trails.
Specify NETWORK for the audit trail type, see Adding Audit Trails with Agent-Based Collection for more information.
For monitoring multiple nodes of an Exadata or RAC database using network trail, create a separate target for each node.
Note:
A network trail can be added with a location that points directly to the network interface card. The attribute is no longer required.
-
If you're upgrading to Oracle Oracle Database Security Central latest version, the trail location will automatically populate based on the value of the
network_device_name_for_hostmonitorattribute, if it was set in the previous version. -
If the attribute was not set, a random value will be selected and populated as the trail location. If this is incorrect, you can drop the trail and add it again with the correct location.
Network trails are monitored hourly. Alerts are generated and email notifications are sent out if network trail is in STOPPED_ERROR state.
Related Topics