Specifying Audit Vault Server System Settings

Learn about configuring Audit Vault Server system settings.

Changing the Primary Audit Vault Server Network Configuration

The Oracle Database Security Central (Oracle DBSecCentral) installer configures the initial network settings for Audit Vault Server during installation. You can change the network settings after installation.

  1. Log in to the Oracle Database Security Central console as a super administrator.

  2. Select Settings.

  3. Select System in the left navigation menu.

  4. Under Configuration, select Network Settings.

  5. In the Network Settings dialog box, edit any of the following fields:

    • Host Name: Enter the fully qualified domain name of the Audit Vault Server. The host name must start with a letter, can contain a maximum of 64 characters, and cannot contain spaces.

      Note:

      • Changing the host name reconfigures the Audit Vault Server automatically. After changing the host name and clicking Save, the system prompts for confirmation and reconfigures the Audit Vault Server. The Oracle Database Security Central console is unavailable for a minimum of 10 minutes. After this, the updated host name appears in the Network Settings dialog box.
      • You can change the host name of the primary and standby Audit Vault Servers by using the primary Oracle Database Security Central console.
    • IP Address: If you need to update the IP address of the Audit Vault Server that was set during the installation, enter the new IP address.

      The IP address is static and must be obtained from the network administrator. The specified IP address may need to be added to routing tables to enable traffic to go between the Audit Vault Server and Database Firewalls.

      Note: If you have a high availability configuration, then you need to unpair the primary and standby Audit Vault Servers before changing the IP address, network mask, and gateway. After you update the network settings on the primary or standby Audit Vault Server, pair the two servers again. After you complete the pairing process, redeploy the Audit Vault Agents to ensure that they are updated with the new settings for the primary and standby Audit Vault Servers.

    • Network Mask: Enter the subnet mask of the Audit Vault Server.

    • Gateway: Enter the IP address of the default gateway (for example, to access the management interface from another subnet). The default gateway must be on the same subnet as the Audit Vault Server.

    • Link properties: Don’t change the default setting unless your network has been configured to not use autonegotiation.

  6. Select Save.

  7. Complete the following post-configuration steps:

    1. If the audit trails are not configured to start automatically, start them manually. See Stopping, Starting, and Autostart of Audit Trails in Oracle Audit Vault Server.
    2. Reconfigure the resilient pair of Database Firewalls if you previously configured them. See Configuring High Availability for Database Firewalls.
    3. If you changed the IP address of the Audit Vault Server, update the IP address information in the Database Firewall configuration. See Specifying the Audit Vault Server Certificate and IP Address.
    4. If you changed the IP address of the Audit Vault Server, redeploy the Audit Vault Agents. See Deploying the Audit Vault Agent.

Related Topics

Changing the Standby Audit Vault Server Network Configuration

Learn how to change the standby Audit Vault Server network configuration.

The network settings of the standby Audit Vault Server can be configured using the primary Oracle Database Security Central console.

To configure the standby Audit Vault Server network settings:

  1. Log in to the primary Oracle Database Security Central console as a super administrator.

  2. Select Settings.

  3. Select System in the left navigation menu.

  4. Under the Configuration sub in the main page, select Network Settings.

  5. In the Network Settings dialog, the Settings sub is selected by default. Select Standby Server radio .

  6. Edit the Host Name. The host name must be a fully qualified domain name of Audit Vault Server. The host name can contain maximum of 64 characters, and cannot contain spaces. The host name of the standby Audit Vault Server cannot be the same as the primary.

  7. Select Save.

    The following confirmation dialog is displayed:

    This operation reconfigures the standby Audit Vault Server. This process takes at least 10 minutes. Do you want to continue?

  8. Select OK.

Note: During this time, the standby Audit Vault Server is unavailable for a minimum of 10 minutes. An error message is displayed in the Network Settings and System Settings dialog on the Oracle Database Security Central console for failing to reach the standby Audit Vault Server.

See Also:

Configuring or Changing the Audit Vault Server Services

Learn how to configure and change the Audit Vault Server sevices.

To configure the Audit Vault Server services:

  1. Log in to the Oracle Database Security Central console as a super administrator.

  2. Select Settings.

  3. Select System in the left navigation menu.

  4. In the Configuration section on the main page, Select System Settings.

  5. Under the DNS, turn on the and enter the IP address in the specific fields. Enter the IP addresses of up to three DNS servers on the network. Audit Vault Server uses these IP addresses to resolve host names. Keep the fields disabled if you do not use DNS servers. Enabling these fields could degrade system performance if you use DNS servers.

    Note: The Client Host (host name of the client) value is displayed in the reports only if the DNS is configured here.

  6. In the dialog, select Web/SSH/SNMP.

  7. Complete the following fields as necessary:

    Caution: When allowing access to Oracle Database Security Central you must be careful to take proper precautions to maintain security.

    • Web Access: If you want to allow only selected computers to access the Oracle Database Security Central console, select IP Addresses and enter specific IP addresses in the box, separated by spaces. Using the default value All allows access from any computer in your site.

    • SSH Access: You can specify a list of IP addresses that are allowed to access the Audit Vault Server through SSH, from a remote console by selecting IP Addresses and entering them in this field, separated by spaces. Using the value All allows access from any computer in your site. Using the value Disabled prevents SSH access from any computer.

    • SNMP Access: You can specify a list of IP addresses that are allowed to access the network configuration of Audit Vault Server through SNMP by selecting IP Addresses. Then enter them in this field, separated by spaces. Selecting All allows access from any computer. If you disable this, it prevents SNMP access. The SNMP community string is gT8@fq+E.

  8. Select Save. A message is displayed.

  9. Select OK in the confirmation dialog.

    See Also: Protecting Your Data for a list of recommendations and precautions to maintain security

Changing the Standby Audit Vault Server System Settings

Learn how to change the system settings for the standby Audit Vault Server.

The system settings of the standby Audit Vault Server can be changed using the primary Oracle Database Security Central console.

To configure the standby Audit Vault Server system settings:

  1. Log in to the primary Oracle Database Security Central console as a super administrator.

  2. Select Settings.

  3. Select System in the left navigation menu.

  4. Under the Configuration sub in the main page, select System Settings.

  5. In the System Settings dialog, the DNS sub is selected by default. Select Standby Server radio .

  6. Enter the IP address in the specific fields. Enter the IP addresses of up to three DNS servers on the network. Audit Vault Server uses these IP addresses to resolve host names. Keep the fields disabled if you do not use DNS servers. Enabling these fields could degrade system performance if you use DNS servers.

  7. In the System Settings dialog, select Web/SSH/SNMP.

  8. Select Standby Server radio .

  9. Complete the Web/SSH/SNMP fields as necessary. The requirements are similar to the primary Audit Vault Server as mentioned in the previous topic.

  10. Select Save.

    The following confirmation dialog is displayed:

    This operation reconfigures the standby Audit Vault Server. This process takes at least 2 minutes. Do you want to continue?

  11. Select OK.

    See Also: Protecting Your Data for a list of recommendations and precautions to maintain security

Changing IP Addresses of Active and Registered Agents

Learn about changing the IP addresses of active and registered Agents.

Use this procedure to change the IP address of a live registered Agents without affecting the functionality of the Audit Vault Agent.

Prerequisites

  1. Stop all audit trails managed by the specific Audit Vault Agent. See section Stopping, Starting, and Autostart of Audit Trails in Oracle Audit Vault Server for more information.

  2. Stop Audit Vault Agent before changing the IP address of the target server. See section Stopping, Starting, and Other Agent Operations for more information to stop the Audit Vault Agent.

To change the IP address of a live registered Agent:

  1. Change the IP address of the machine on which agent is installed.

  2. Change the IP address of the previously registered Agent entity of Oracle Database Security Central using the Oracle Database Security Central console or Audit Vault command-line interface.

  3. Run the following to start the Audit Vault Agent with the -k option:

    agentctl start -k
  4. Enter an Activation Key.

  5. Start Audit Trails.

See Also: Changing the IP Address on a Single Instance of the Database Firewall Server

Updating the Audit Vault Server IP Address in the NTP Configuration File

After updating the Audit Vault Server IP address, if you’re using Network Time Protocol (NTP), you need to update the /etc/ntp.conf file.

Prerequisite

Update the Audit Vault Server IP address. See Changing the Primary Audit Vault Server Network Configuration.

Procedure

  1. Log into the Oracle Database Security Central console as an administrator.

  2. Select Settings.

  3. Select System in the left navigation menu.

  4. Under Configuration, select System Settings.

  5. Select Time & Keyboard in the System Settings dialog box.

  6. Select Set Manually.

    This updates /etc/ntp.conf.

  7. Check the /etc/ntp.conf file to verify that the IP address has changed.

  8. In the System Settings dialog box, select Use NTP and enter the NTP server IP addresses or names.

    For details on the field values, see Specifying the Server Date, Time, and Keyboard Settings.

  9. Select Save.

Configuring Security Advisor

Security advisor enables users to ask natural-language questions about Oracle Database Security Central and receive AI-generated responses. Questions may relate to guidance on how to perform tasks in Oracle DBSecCentral (documentation and procedures) or to data collected in Oracle DBSecCentral (for example, user assessment data, audit records, and so on).

Prerequisites:

To use the feature, you must have an Oracle Cloud Infrastructure (OCI) account and configure the required OCI credentials in the Oracle Database Security Central console.

Ensure that you have enabled DNS on Audit Vault Server.

To configure Security advisor:

  1. Log in as a Super Administrator.

  2. Go to Settings, then System.

  3. Under Configuration, select Security advisor configuration.

  4. In the Security advisor configuration dialog box, provide the required OCI details.

  5. Select Save.

  6. Log out and log in again.

Security Advisor usage and data handling

Security Advisor securely stores the OCI credentials you provide in the Audit Vault Server. If these credentials are changed, you must recreate the configuration with the updated credentials.

To delete the configuration:

  1. Log in as a Super Administrator.

  2. Go to Settings, then System.

  3. Under Configuration, select Security advisor configuration.

  4. Select Delete.

  5. In the Do you want to delete security advisor configuration? dialog, select OK.

  6. Log out and log in again.

Data collected by the Audit Vault Server is transmitted to OCI only for the purpose of processing and responding to user queries. Security Advisor does not retain this collected data on OCI servers.

All communication between the Audit Vault Server and OCI is secured using HTTPS with TLS 1.2 or later to protect data in transit.

Security Advisor routes all “how-to” queries to the US West (Phoenix) region, regardless of the OCI region specified in the configuration. Queries that require analysis of collected data are sent to the OCI region selected during configuration.

Caution: Security Advisor uses OCI GenAI. To use this feature, ensure that you have an OCI account created. Responses generated by Security Advisor are AI-generated and may contain inaccuracies. Always review and validate the results before taking any action.

Configuring HTTP proxy for Security Advisor

In some cases, you may need to configure HTTP proxy to allow Security Advisor to access the external OCI REST endpoint. To enable proxy support for HTTP connections, complete the following steps on the Audit Vault Server.

To configure proxy access:

  1. Log in to the Oracle DBSecCentral server as root.

  2. Switch to the Oracle user:

    su - oracle
  3. Unset the PDB session variable:

    unset ORACLE_PDB_SID
  4. Connect to the database as sysdba:

    sqlplus / as sysdba
  5. Create an ACL entry for OCI access:

    exec dbms_network_acl_admin.append_host_ace(
      host =>'*.oci.oraclecloud.com',
      lower_port => 443,
      upper_port => 443,
      ace => xs$ace_type(
        privilege_list => xs$name_list('HTTP','HTTP_PROXY'),
        principal_name => 'C##CLOUD$SERVICE',
        principal_type => xs_acl.ptype_db
      )
    );
  6. Create an ACL entry for the proxy server:

    exec dbms_network_acl_admin.append_host_ace(
      host => '<your proxy URI address>',
      lower_port => <your proxy lower port>,
      upper_port => <your proxy high port>,
      ace => xs$ace_type(
        privilege_list => xs$name_list('HTTP_PROXY'),
        principal_name => 'C##CLOUD$SERVICE',
        principal_type => xs_acl.ptype_db
      )
    );
  7. Set the database HTTP proxy property:

alter database property set http_proxy='<your proxy URI address>';

Note: Use the actual proxy hostname and port range for your environment. These settings are required so DBMS_CLOUD PLSQL API can connect to the OCI REST services for Security Advisor.