Viewing and Changing Settings for a Target

You can view and change settings such as policy settings, entitlement data, or a list of audit trails for a target.

Viewing Audit Data Collection and Database Firewall Monitoring Details for Targets

You can view audit data collection and database firewall monitoring details for each target.

  1. Log into the Oracle Database Security Central console as an auditor.

  2. Select Targets.

  3. Select a target from the list.

    On the target details page, you can view the following information about the target:

    • Connect String

    • Description

    • Retention Policy displays the data retention policy that is currently in effect for the target. You can also select a new policy here.

    • Audit Data Collection displays details about the current audit trails that are configured for the target. Details include the audit trail location, trail type, status, name of the agent, time the collection was last started, and time until which data was collected.

    • For database targets, the Database Firewall Monitoring displays details about the current database firewall monitoring points that are configured for the target. Details include the connection details, database firewall name, status, traffic source, proxy port, and deployment mode. You can also view and change the database firewall monitoring policy here.

Related Topics

Scheduling the Retrieval of Audit Policies for an Oracle Database

To retrieve audit policies for an Oracle Database, schedule an audit policy retrieval job for the target.

  1. Log in to Oracle Database Security Central Console as an auditor.

  2. Select Policies.

  3. On the Policy Console, select the databases to schedule retrieval for from the Policies retrieval schedule for Oracle Databases table.

  4. Select Schedule Retrieval.

  5. Select the policy(ies) type(s) to retrieve.

  6. Set the retrieval schedule.

  7. Select Save.

Related Topics

Retrieving User Assessment Data for Oracle Database Targets

To retrieve data for user assessment snapshots, submit or schedule a user assessment retrieval job for an Oracle Database target.

When an Oracle Database is registered as a target in DBSecCentral, the first user assessment job is submitted automatically. You can then manually submit the job to run immediately or schedule it to run at a specified frequency, such as weekly or monthly.

Note: All assessment data will be purged after 18 months from the time of data retrieval.

For implementing Database Security Posture Management (DSPM), it is recommended to schedule the User Assessment retrieval job for each target.

To create or change a user assessment retrieval job:

  1. Log in to Oracle Database Security Central Console as an auditor.

  2. Select Policies.

  3. Select Schedule Retrieval.

  4. User Assessment:

  5. Select Save.

Related Topics

Retrieving Security Assessment Data for Oracle Database Targets

To retrieve data for the security assessment reports, submit or schedule the security assessment retrieval job for an Oracle Database target.

When an Oracle Database is registered as a target in DBSecCentral, the first security assessment job is submitted automatically. You can then manually submit the job to run immediately or schedule it to run at a specified frequency, such as weekly or monthly.

Note: All assessment data will be purged after 18 months from the time of data retrieval.

For implementing Database Security Posture Management (DSPM), it is recommended to schedule the Security Assessment retrieval job for each target.

To create or change a security assessment retrieval job:

  1. Select Policies.

  2. Select Schedule Retrieval.

  3. Security Assessment:

  4. Select Save.

Related Topics

Retrieving Sensitive Data for Oracle Database Targets

To identify privileged users and sensitive data for data discovery, submit or schedule the sensitive data retrieval job for an Oracle Database target.

When an Oracle Database is registered as a target in DBSecCentral, the first data discovery job is submitted automatically. You can then manually submit the job to run immediately or schedule it to run at a specified frequency, such as weekly or monthly.

To create or change a sensitive data discovery job:

  1. Log in to Oracle Database Security Central Console as an auditor.

  2. Select Policies.

  3. Select Schedule Retrieval.

  4. Sensitive Objects:

    • To disable the schedule, follow these steps:
      1. Select Create/Update Schedule.

      2. Select Disable.

    Note: Disabling the schedule does not revoke the user privileges for data discovery on the Oracle Database. Disabling the schedule only stops the schedule and prevents the sensitive data from updating.

  5. Select Save.

Related Topics

Activating Stored Procedure Auditing

To retrieve data for the stored procedure auditing reports, schedule the stored procedure auditing retrieval job for a database target.

  1. Select Policies.

  2. Select Schedule Retrieval.

  3. Under Stored Procedure Auditing, follow these steps:

    1. Select Create/Update Schedule.

    2. Select Enable.

    3. Enter the start date and time and the repetition frequency.

  4. Select Save.

Note: See Oracle Database Security Central Administrator’s Guide for information about collecting stored procedure changes from a target database. An Oracle Database Security Central administrator must run scripts to set up the correct user privileges on the target database.

Related Topics

Viewing a List of Audit Trails for a Target

An Oracle Database Security Central starts and stops audit trails.

As an auditor, you can view lists of audit trails for targets you have access to. You can see the trails collected for one or more targets.

  1. Log into the Oracle Database Security Central console as an auditor.

  2. Select Targets.

  3. Select Audit Trails in the left navigation menu.

  4. Select a target from the list displayed. The details pertaining to the specific target is displayed on the screen.

  5. Scroll down. The Audit Data Collection tab is selected by default.

    The audit trails for the target are listed in a table with the following columns:

    • Audit Trail Location

    • Audit Trail Status

    • Audit Trail Type

    • Collection Agent

    • Last Start At

  6. Optionally, select on the column name title for the following options:

    • Sort Ascending

    • Sort Descending

    • Hide Column

    • Control Break

    There is search field and other options available.

    See Also: Logging in to the Oracle Database Security Central Console

Selecting a Firewall Policy

If a target is a database monitored by a Database Firewall, you can upload or change the firewall policy assigned to the target.

  1. Log into the Oracle Database Security Central console as an auditor.

  2. Select Policies.

  3. Select Database Firewall Policies tab in the left navigation menu.

  4. A list of User-defined Database Firewall Policies and Pre-defined Database Firewall Policies are displayed on the screen.

  5. Select a specific target to view the firewall policy defined. You can make changes to the policy here from this screen.

    See Also:

Viewing a List of Database Firewall Monitoring Points

An Oracle Database Security Central administrator creates monitoring points for database targets monitored by Database Firewall.

As an auditor, you can see the Database Firewall monitoring points configured for the database targets you have access to. You can see the monitoring points for one target or for all your targets.

Viewing a List of Monitoring Points for a Database Target

You can access a list of monitoring points for a database target.

  1. Log into the Oracle Database Security Central console as an auditor.

  2. Select Targets.

    The Targets sub tab in the left navigation menu is selected by default. The main page lists all the targets configured.

  3. Select a specific target.

  4. Scroll down and select on Database Firewall Monitoring sub It contains a list of all the Database Firewall monitoring points associated with this target. This section is not visible if the target is not a database.

    See Also: Logging in to the Oracle Database Security Central Console

Viewing a List of Monitoring Points for All Your Target Databases

You can access a list monitoring points configured for all your database targets.

  1. Log in to the Oracle Database Security Central console as an auditor.

  2. Select Targets.

  3. From the left navigation menu, select Database Firewall Monitoring.

  4. The main page lists all the targets and the status of the corresponding Database Firewall monitoring points. Select the name of the specific target to see its details.

    See Also: Logging in to the Oracle Database Security Central Console

Setting a Data Retention (Archiving) Policy

The data retention policy for a target determines how long audit data is retained for that target.

An Oracle Database Security Central administrator creates retention policies, and an auditor selects one of the available policies to assign to a target. If you do not select a retention policy for a target, the default retention policy will be used (12 months retention online and 12 months in archives before purging). Do not set the retention policy after data collection has started from the target. After the retention period is reached, the archived data is purged and cannot be retrieved. A new retention policy takes effect as of the date you select the policy, but does not apply to existing data.

  1. Log in to the Oracle DBSecCentral console as an auditor.

  2. Select Targets.

    The Targets sub tab in the left navigation menu is selected by default. The main page lists all the targets configured.

  3. Select a target from the list.

  4. The Retention Policy field displays the duration of the retention and archival policy for the specific target.

  5. To set or change the retention policy, select the edit icon next to the Retention Policy field. Select from the available retention policies.

  6. Select Save.

See Also: