Audit Vault Server Post-Installation Tasks
Complete these recommended post-installation tasks after installing the Audit Vault Server.
-
Complete the steps in Accessing the Audit Vault Server Post-Install Configuration Page and set up user names and passwords.
-
Apply the patch to remove deprecated ciphers after an Audit Vault Server install or upgrade:
Deprecated-Cipher-Removal.zip. -
Review the DNS and NTP system service configuration. See Configuring or Changing the Oracle Audit Vault Server Services.
-
Oracle Database Security Central supports high availability for Audit Vault Server by either deploying on Oracle Real Application Clusters (Oracle RAC) or by deploying with a primary and standby server. See High Availability in Oracle Database Security Central.
-
Register the targets for monitoring with Oracle Database Security Central. See Configuring Targets, Audit Trails, and Database Firewall Monitoring Points.
-
Configure the data retention policy for every target before configuring audit trails. See Configuring Archive Locations and Retention Policies.
-
Configure each audit trail for native audit collection. See Preparing Targets for Audit Data Collection.
-
Deploy an Audit Vault Agent on the machine where the target is installed or on a machine that can connect to the target.
Note: You can use agentless collection instead of the Audit Vault Agent for up to 20 Oracle Database table audit trails. In addition, you can also use agentless collection for Microsoft SQL Server directory audit trails for
.sqlauditand.xel(extended events). The total number of audit trails for agentless collection should not exceed 20. See Adding Audit Trails with Agentless Collection. -
Enable native database auditing on the target.
-
Review and configure the audit trails for the target.
-
Configure the audit trail cleanup wherever necessary.
-
-
For Oracle Database targets, consider provisioning Oracle recommended audit policies. See Creating Audit Policies for Oracle Databases.
-
For network monitoring requirement, install Database Firewall appliance and register it with Audit Vault Server. See Installing Audit Vault Server or Database Firewall and Registering Database Firewall in Audit Vault Server
-
Consider configuring alert policies. See Creating Alerts.
Note:
-
Set the user names and passwords of the Audit Vault Server administrator and auditor, as well as the passwords of its root users. You can also set the time and domain name service (DNS) servers of the Audit Vault Server.
-
The Audit Vault Server reads the audit log from the target that contains the time stamp of the event. Without synchronization of the AVS and target, events may appear to be archived to the Audit Vault Server before they occur and alerts may appear to be sent before their triggering events occur.