Installing and Enabling the Host Monitor Agent

Use this process to install and enable the Host Monitor Agent.

  1. Deploy the Host Monitor Agent on all the database servers where the database is running.

  2. Register the target.

  3. Create a Database Firewall monitoring point in Monitoring (Host Monitor) mode.

  4. Change the Database Firewall policy for the target from Default to the appropriate policy, if needed.

    See Types of Database Firewall Policies for the different policy types.

  5. Configure a NETWORK audit trail for the monitored target.

    Note:

    • The Host Monitor Agent is supported on Linux, Solaris, AIX, and Windows platforms. It can monitor any database that is supported by the Database Firewall. See Table C-1 for supported databases.

    • The Host Monitor Agent supports the Solaris IPNET link type on Oracle Solaris SPARC64 and x86-64.

    • The Host Monitor Agent supports the Ethernet (EN10MB) link type for all supported platforms.

    • The Host Monitoring Agent can inspect SQL commands issued using local connections to the database through loopback (non-Oracle and Oracle) and bequeath (Oracle) when the Database Firewall is deployed in Monitoring (Host Monitor) mode. With this feature, the Host Monitoring Agent has complete visibility into database activities performed by all users including administrators accessing the database server as such. For a comprehensive visibility, it is recommended to augment network monitoring with database auditing. Database auditing running inside the Oracle Database has complete visibility into the internal jobs or procedure execution which typically network monitoring might not have access to. Database auditing cannot be bypassed by the use of synonyms or dynamically generated names, while network monitoring policies should be trained for all such possible combinations to make it foolproof.

Related Topics

Host Monitor Agent Requirements

The Host Monitor Agent has different requirements for installation, depending on the platform.

To install the Host Monitor Agent on the Windows platform, follow these requirements:

To install the Host Monitor Agent on a Linux, Unix, AIX, or Solaris platform, follow these requirements:

Related Topics

See Also: Enabling and Using Host Monitoring for host monitoring instructions and prerequisites.

Validation During Host Monitor Agent Deployment

Learn about validations performed by Oracle Oracle Database Security Central when deploying the Host Monitor Agent.

The following validations are performed on the Linux/Unix/AIX/Solaris platforms when deploying the Host Monitor Agent. These requirements are mandatory and must be complied with; without meeting them, the Host Monitor Agent installation cannot be completed.

Registering the Host Machine That Will Run the Host Monitor Agent

Learn how to register the host machine (such as a database server) on the Audit Vault Server.

To register a host on the Audit Vault Server, see Registering Hosts on the Audit Vault Server.

Deploying the Audit Vault Agent and Host Monitor Agent

Learn how to deploy the Audit Vault Agent and Host Monitor Agent on platforms like Linux, Solaris (x86-64), Solaris (Sparc64), AIX, and Windows.

Deploying the Host Monitor Agent on a Windows Host Machine

On Windows, the Host Monitor Agent is installed by the Audit Vault Agent. There are no separate Host Monitor Agent installable bundles available for download in the Oracle Database Security Central console. No separate action is required to install the Host Monitor Agent on Windows.

Follow these instructions before installing the Host Monitor Agent or updating from an older Oracle DBSecCentral release.

Prerequisites

Related Topics

Deploying the Host Monitor Agent on a Unix Host Machine

Learn about deploying the Host Monitor Agent on Unix hosts.

Prerequisite Host Monitor Agent Requirements

  1. Before you install the Host Monitor Agent, ensure you have deployed the Audit Vault Agent.

    See Deploying the Audit Vault Agent.

  2. Log in as root and identify a root-owned directory on the local hard disk, such as /usr/local, where you will install the Host Monitor Agent.

    Note: The entire directory hierarchy must be root-owned. All the directories in this hierarchy must have read and execute permission for other users or groups, but not write permission.

  3. Log in to the Oracle Database Security Central console as an administrator.

  4. Select Agents.

  5. In the left navigation menu, Select Downloads.

  6. On the page listing the agent software, select Download button corresponding to your Unix version, and then save the .zip file to the root-owned directory (on the local hard disk) you identified in Step 2, for example /usr/local.

  7. As root user, unzip the Host Monitor Agent file, agent-<platform>-hmon-one.zip (for example, agent-linux-x86-64-hmon-one.zip).

    This creates a directory named hm. This is your HM_Home directory, which in this example is /usr/local/hm.

  8. Ensure that the hostmonsetup file (in the hm directory) has the execute permission for the owner.

  9. Run the following command from the HM_Home directory:

    <HM_Home>/hostmonsetup install [agentuser=<Agent_Username>] [agentgroup=<Agent_Group>]
    • HM_Home - The directory created in Step 7.

    • Agent_Username - (Optional) Enter the user name of the user who installed the Audit Vault Agent (the user who executed the java -jar agent.jar command).

    • Agent_Group - (Optional) Enter the group to which the Agent_Username belongs.

    See Also: Using Oracle Database Security Central Console

Creating a Target for the Host-Monitored Database

Learn how to create a target for the host-monitored database.

To create a target, see Registering or Removing Targets in Audit Vault Server.

Creating a Monitoring Point for the Host Monitor Agent

A monitoring point is a logical entity on the Database Firewall host that contains the configuration and rules for monitoring the SQL traffic that is received.

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Targets. The Targets in the left navigation menu is selected by default.

  3. Select and select a specific target from the list.

  4. From the Database Firewall Monitoring section on the main page, select Add. The Database Firewall Monitor dialog is displayed.

  5. In the Core, enter the name for the Database Firewall instance or select one from the list.

  6. Select Monitoring (Host Monitor) as the deployment type from the list. In this mode, the Database Firewall can only monitor the SQL traffic.

  7. Choose a Network Interface Card for the Database Firewall host from the list.

    Note: You must select a network interface card which has an IP address configured. All the network interface cards which have an IP address configured are displayed in the Network Interface Card list. It is recommended to select a network interface card that is not used as a Management Interface. This segregates the traffic from Host Monitor Agent to the Database Firewall and the traffic from the Database Firewall to Audit Vault Server.

  8. In the Connection Details section, select one or more targets for which the traffic needs to be monitored. You can Add the targets from the list.

    Note:

    • For Exadata or Oracle RAC, enter both the physical and virtual IP’s of the nodes but not the SCAN IPs in the Target Connections field.

    • For Oracle RAC, enter the IP address of the individual RAC node in the Target Connections field.

    Enter the following information for each available connection of the database. Select Add to add more targets and enter the following fields:

    • Host Name / IP Address

    • Port

    • Service Name (Optional, for Oracle Database only). SID can be used in this field. To enter multiple service names and/or SIDs, enter a new line for each of them, and then select Add. Multiple entries are allowed for monitoring only mode.

      • You can use one proxy port and specify multiple OSNs on the target database that are going to be processed. Specify the OSNs in a list delimited by the “" character. For example, target1\target2\target 3.

    Note: For Linux hosts with multiple network devices, add a row for every network device from which the database traffic is expected to arrive.

  9. Select Advanced, enter the number of Database Firewall Monitor Threads (minimum value is 1). This controls the number of traffic handling threads in the Database Firewall monitoring point. The default value is 1. This value can be increased when high transactions are reported (per second traffic) and packet dropped messages are reported in the /var/log/messages file. Contact Oracle Support while changing this number.

  10. Select the checkbox for Decrypt With Network Native Encryption Key field only for Oracle Database targets. This is for enabling decryption of traffic if the database is using Oracle Native encryption. Decrypt with network native encryption key option also supports retrieval of session information for Oracle Database. Complete the remaining fields as applicable.

    For Oracle standalone database targets, enter the IP address of the database listener in the IP Address field.

    For Microsoft SQL databases, the field is Retrieve session information from target DB. Retrieving session information is not available for any other non-Oracle database types.

    Select this field to retrieve session information such as OS User Name, DB User Name, client application name, and IP address from the target database.

    Note: Ensure the Database Firewall is allowed to make a network connection to the above mentioned database.

  11. Select Save at the bottom of the dialog to save the configuration of the monitoring point.

    The new monitoring point appears in the list and starts automatically.

    Note: Default Database Firewall Policy will be applied for this Database Firewall Monitoring Point. This message is displayed at the bottom of the dialog.

  12. Select Save in the main page.

  13. To stop or restart the monitoring point, select it from the Database Firewall Monitoring section and select Stop or Start.

    See Also: Configuring Database Firewall Monitoring Points

Create a Network Audit Trail

Learn how to create network audit trails.

Specify NETWORK for the audit trail type, see Adding Audit Trails with Agent-Based Collection for more information.

For monitoring multiple nodes of an Exadata or RAC database using network trail, create a separate target for each node.

Note:

A network trail can be added with a location that points directly to the network interface card. The attribute is no longer required.

Network trails are monitored hourly. Alerts are generated and email notifications are sent out if network trail is in STOPPED_ERROR state.

Related Topics