View and Manage Audit Profiles

You can view audit profiles for target databases, update them, compute audit volume with them, move them to different compartments, and add tags to them.

Audit Profile Details

You can view the following information in an audit profile:

  • Profile name (editable)
  • Target database to which the audit profile belongs
  • Profile description (editable)
  • Profile Oracle Cloud Identifier (OCID)
  • When the audit profile was created and last updated
  • Compartment in which the audit profile resides. This is always the same compartment to which the target database was registered.
  • Whether the option to override the global paid usage setting is selected
  • Whether paid usage is selected for the target database
  • Whether the option to override the global retention period is selected
  • Online and offline retention periods
  • Audit volume (number of audit records collected by Oracle Data Safe from the target database that are applied to the current month's billing cycle)
  • Available audit trail locations

    Note:

    For Active Data Guard associated target databases, you will see:
    • A UNIFIED_AUDIT_TRAIL collecting records from the AUDSYS.AUD$UNIFIED table of the primary database. For example, TABLE:PRIMARY.
    • A UNIFIED_AUDIT_TRAIL collecting audit records from the operating system spillover files of the primary database. For example, FILE:database_unique_name1.
    • A UNIFIED_AUDIT_TRAIL collecting audit records from the operating system spillover files of each peer database that is registered. For example, FILE:database_unique_name2.
    You can distinguish the UNIFIED_AUDIT_TRAIL that point to the operating system spillover files by the associated database unique name.
  • Tags
  • Monthly available data in the target database
  • Monthly collected online audit data in Oracle Data Safe
  • Monthly collected offline audit data in Oracle Data Safe

View an Audit Profile for a Target Database

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of the target database for which you want to view audit profile details. The Audit Profile Details page for the selected target database is displayed.
  4. On the Audit Profile Details tab, view information about the audit profile.
  5. To view the monthly available audit data in the target database, collected online audit data in Oracle Data Safe, and collected offline data in Oracle Data Safe, scroll down and view the table in the Compute Audit Volume section.

Note:

You can also discover new audit trails for a target database from the Audit Profiles Details page. See Discover Audit Trails for a Target Database

Update the Name and Description of an Audit Profile

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of the target database.
  4. To change the name of the audit profile, click the pencil icon next to the profile name and then enter the new name.
  5. To change the description of the audit profile, click the pencil icon next to the profile description, edit the description and click the save icon.

Override Global Retention Periods for a Target Database

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of the target database for which you want to update the retention period. The audit profile for the selected target database is displayed.
  4. Click Update Retention. The Update Retention dialog box is displayed.
  5. Select Yes at Do you want to override the global retention settings?.
    Your configuration will override the global retention policy settings for your target database.
  6. For Online Retention, enter the number of months you want to store audit data online for immediate analysis.
  7. For Offline Retention, enter the number of months that you want to store audit data offline.
  8. (Optional) Depending on how much audit data you have, there may be additional costs. Click the Pricing Details link to learn more.
  9. Click Update Retention.

Compute Available Audit Volume on a Target Database

You can query and view the monthly number of audit records collected on your target database from a particular date and time. It is possible to show audit records available in the target database. but not collected yet in Oracle Data Safe. Knowing how many audit records exist on your target database and when the records were generated can help you to determine when to start collecting audit records in Oracle Data Safe and manage the billing.

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of your target database. The audit profile for the selected target database is displayed.
  4. Scroll down to the Compute Audit Volume section.
  5. Click Available on Target Database. The Compute Available Volume dialog box is displayed.
  6. For Select Start Date, click the box and configure a start date and time from which you want to view the available volume. Oracle Data Safe will list the audit records collected on your target database for each month following the date that you set here.
  7. Click Compute. The number of audit records collected on your target database is updated next to each audit trail. For example, you might see a value like 0.4M next to UNIFIED_AUDIT_TRAIL, which means there are 0.4 million individual audit records collected in the UNIFIED_AUDIT_TRAIL on your target database.
    For Active Data Guard associated target databases, you will see:
    • A UNIFIED_AUDIT_TRAIL collecting records from the AUDSYS.AUD$UNIFIED table of the primary database. For example, TABLE:PRIMARY.
    • A UNIFIED_AUDIT_TRAIL collecting audit records from the operating system spillover files of the primary database. For example, FILE:database_unique_name1.
    • A UNIFIED_AUDIT_TRAIL collecting audit records from the operating system spillover files of each peer database that is registered. For example, FILE:database_unique_name2.
    You can distinguish the UNIFIED_AUDIT_TRAIL that point to the operating system spillover files by the associated database unique name.

Compute Collected Audit Volume for a Target Database

You can query and view the monthly number of audit records collected by Oracle Data Safe for your target database for a specific time period.

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of your target database. The audit profile for the selected target database is displayed.
  4. Scroll down to the Compute Audit Volume section.
  5. Click Compute Collected Volume. The Compute Collected Volume dialog box is displayed.
  6. For Start Month, configure a start month from which you want to view the number of audit records.
  7. For End Month, configure an end month.
  8. Click Compute. The number of audit records collected by Oracle Data Safe is updated in the Collected in Data Safe (Online) column in the table.

Override Global Paid Usage for a Target Database

You can choose to collect or not collect audit records beyond the free limit of one million audit records per month per target database. Additional charges may apply. By default, all target databases will inherit the global paid usage settings, but this can be overridden for each target database.

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of your target database for which you want to opt in for paid usage. The audit profile for the selected target database is displayed.
  4. Click Update Paid Usage. The Update Paid Usage dialog box is displayed.
  5. Select Yes at Do you want to override the global paid usage settings?.
  6. Select or deselect Paid Usage.
  7. Click Update Paid Usage.

Move an Audit Profile

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of the target database that has the audit profile that you want to move. The audit profile for the selected target database is displayed.
  4. Click Move Resource. The Move Resource to a Different Compartment dialog box is displayed.
  5. From the drop-down list, select a different compartment.
  6. Click Move Resource. The audit profile is moved immediately.

Add Tags to an Audit Profile

  1. Under Security Center, click Activity Auditing.
  2. Under Related Resources, click Audit Profiles.
  3. On the right, click the name of the target database that has the audit profile to which you want to add tags The audit profile for the selected target database is displayed.
  4. Click Add Tags. The Add Tags dialog box is displayed.
  5. Configure one or more tags, and then click Add Tags.