About Upgrading to Oracle Database Security Central
Oracle Database Security Central (Oracle DBSecCentral) provides an out-of-place upgrade method from Oracle Audit Vault and Database Firewall 20.14 and later.
In this approach:
-
The existing 20.14 (or higher) Audit Vault Server is referred to as the source Audit Vault Server.
If you are not yet on AVDF 20.14 or higher, you will need to upgrade to 20.14 or higher before upgrading to Oracle Database Security Central. See Patching Oracle Audit Vault and Database Firewall Release 20 for more information.
-
The newly provisioned DBSecCentral Audit Vault Server is referred to as the destination Audit Vault Server.
Out-of-Place Upgrade Workflow
The upgrade process consists of three major stages:
-
Set up source and destination Audit Vault Server.
Prepare both environments and ensure configuration alignment.
-
Perform the out-of-place upgrade for Audit Vault Server.
This step includes data transfer and system upgrade.
Example timing:
- Approximately 3.5 hours for an 840GB standalone Audit Vault Server
- About 4 hour for a 2TB stand alone Audit Vault Server.
- The data migration step of the upgrade takes about 10 minutes for 840GB and about 28 minutes for 2TB.
-
Post-Upgrade Tasks
-
Upgrade Database Firewalls
-
Migrate Audit Vault Agents and Host Monitor Agents
-
Perform validation and cleanup
-
Benefits of Out-of-Place Upgrade
-
No downtime is required for setup, system, and software upgrade. Downtime is required when system is ready for data migration.
-
Reduces operational risk compared to in-place upgrades.
-
Recovery is quick and is not dependent on the size of the data. Recovery process takes about the same time as source setup.
Pre-Upgrade Requirements
Before starting the out-of-place upgrade:
-
Create the destination Audit Vault Server. Oracle recommends that the destination Audit Vault Server hardware configuration should be the same or better than the source Audit Vault Server. The database (ASM) storage on the destination Audit Vault Server must be at least 15% more in each disk group (EVENTDATA, SYSTEMDATA and RECOVERY). See the Extending Storage in the Oracle Database Security Central Administrator’s Guide.
-
If you plan on configuring high availability using Oracle RAC, you must first upgrade your 20.14 or higher instance to a standalone DBSecCentral system and then configure Oracle RAC. This means that you must create a standalone destination Audit Vault Server before beginning the out-of-place upgrade process. For more information see Deploying Oracle DBSecCentral in High Availability Configuration Using Oracle Real Application Clusters (Oracle RAC).
-
If you configure the source Audit Vault Server for high availability using a standby server and you want to continue operating in a high availability configuration after the upgrade, you must use a standby server to configure the destination Audit Vault Server for high availability before starting the upgrade.
-
If you have scp/smb archive locations, you must move that data to NFS archive locations. The out-of-place upgrade does not handle migration of scp/smb locations.
-
The number of NFS archive locations must be the same on the destination and source Audit Vault Servers.
-
The destination Audit Vault Server must have more storage capacity than the source Audit Vault Server. The destination Audit Vault Server must have at least 15% more disk space than the source Audit Vault Server.
If your deployment uses both HDD and SAN storage, ensure that sufficient disk space is available on either storage type. For each disk group (EVENTDATA, SYSTEMDATA, and RECOVERY), allocate 15% more disk space on the destination Audit Vault Server(s) than is available on the source Audit Vault Server. If you are configuring a primary and standby destination Audit Vault Server, ensure that both destination servers have the same disk space allocation for each disk group.
Estimated Time to Upgrade
The total upgrade time for an 840 GB source Audit Vault Server is approximately 3 to 3.5 hours. The following table summarizes the approximate duration of each upgrade phase:
| Upgrade Phase | Approximate Duration |
|---|---|
| Destination setup | 3 minutes |
| Isolation | 1 minute |
| Database upgrade | 35 minutes |
| Post migration | 60 minutes |
| Database Firewall Upgrade | 45 minutes |
| Full agent migration | 30 minutes |
The CLONEPDB step within the autoupgrade process is most dependent on source Audit Vault Server size. For a 840GB source Audit Vault Server it is estimated to take about 10 minutes. However, you should plan for an additional 1.5 minutes per 100GB over 840GB.
-
Post migration: 60 minutes
-
Database Firewall Upgrade: 45 minutes
-
Full agent migration: 30 minutes