Auditing session

Os : RHEL 2.1
Oracle 9.2.0.8
Dear all,
Recently I have enabled session level auditing. I have changed the audit_trail parameter to true and as a sys user issued "audit session" command.
Now the aud$ table is getting populated but I just wanted to know the IP address of the client who are creating the session. All other requred information are gathering except IP address of the client. Is there any way veiw which I can see those information or do I have to change the audit option?
Regarding
Nishant

Did you issue AUDIT CREATE SESSION? Yes
The link which you have provided is very useful, thanks..
Just ping the terminal from $ promptThe terminal colunm is not giving a clear picture, sometimes its coming like "unknown", moreover the the ping terminal is not working.
I think to get the IP address I need to track manually by writing trigger, I need to check Pavan Kumar's query..
Thanks to every one...
Nishant

Similar Messages

  • Importing Audition Sessions

    I have number of Adobe Audition CS5 sessions I need to import into Logic Pro 9 and Nuendo. What's the best way to do it, without sacrificing any quality? Can I include the effects and EQ in the import?

    You will need to decide which is the best Export format from Audition.
    http://helpx.adobe.com/audition/using/saving-exporting-files.html
    Probably OMF, read up on it above.. effects are not included as each program has it's one set of effects, cross referencing would be horrendus, EQ is not included either, just basic placement of files.
    An OMF file can contain all of the audio files OR, it can reference their location.
    The're also the Final Cut Interchange (XML) format, if it's a recent Nuendo can probably seal with those.

  • Audition sessions and Pro Tools

    I was just wondering if there is any way that Pro Tools 8 can open up Audition files. Is there a 3rd party software that allows for that, or is there a particular format that works between Audition 3 and Pro tools 8?
    Thank-you

    AA Translator may have the answer but maybe not PT8 yet.
    http://www.aatranslator.com.au/

  • Can I load adobe audition 3.0 sessions to garage band?

    Can I load adobe audition 3.0 sessions to garage band?

    I don't believe you can in its native format. However, you can certainly add a stereo mix or individual audio tracks from an an Audition session into GB (just as you would add any *standard* audio file to GB).

  • How do I adjust the tempo of a drum track inserted in Audition multitrack session?

    (Note: for the Audition 101 user)  In a multitrack Audition session, what is the best way to adjust the tempo of an inserted drum track to sync up with the already metronome-established tempo of recorded rhythm tracks (guitars & vocals)?

    Time Stretch the clip. Either by trial and error or, if you know the tempo of the inserted track, by calculation.

  • Audition CS 6 - multitrack session tracks offline

    Hi everyone.
    This is a true nightmare. Yesterday I was recording a live concert in Audition CS 6 using a multitrack session. When I checked the footage and sound files at home I couldn't believe what I saw. Half of the session was offline!! Nowhere to find. What shall I do about it?
    I saved the session just like any other one thinking that this would be enough to save the .wav files on my hard drive.
    Here's the background to it:
    I had about 16 tracks coming from a Behringer X32.
    The band was playing two sets, so I did one short break before recording the second part of the concert. All in one Audition session.
    So as the gig was over I had all input channels split into two long tracks. Everything fine. Now due to lack of time I couldn't export every single track as backup.
    So I just saved the session, shut down my computer and thought it would be alright.
    Is there a way to get the files of the first part of the concert back? How can this be, if it's in one and the same multitrack session?
    I didn't shut down Audition during the break.
    I read some threads about this very issue. But noone had a solution.
    Please, I need help on this one. It's urgent!!

    I located the directory of the lost files. (C:\User\AppData\Roaming\Adobe\Audition\5.0\528780dd.......)
    But there are no files in there anymore. No temp folders.
    They do only exist if I'm running Audition. Atfer closing it they are gone.
    I also tried several recovery tools, but this didn't work out either.
    What can I do? It is driving me insane. I can't afford a professional to recover the files.
    There must be another way!

  • Audition 5.5 crashing - unable to open sessions

    I have my CS 5.5 Production Premium up and running for a couple of weeks and now I am trying to finish 2 songs which I have recorded through Audtion. The problem is while I am doing the editing, my system freezes and the worst thing is that I am not able to open audition sessions once it crashes.  When it happened to me first, I took precaution and started using Save As and saved 2 versions of the session. However, when the system froze again, I could not open both the versions of sessions. Obviously the .wav files used by both are same. I also read somewhere that the problem could be one of the .wav files used in the session. Is there any way to identify which file is giving a problem? What could be wrong here?
    My set up is as follows:
    Intel i7 Quad core 8 GB DDR 5 RAM
    Nvidia Quadro 2000d
    128 GM SSD – System Drive
    2 x 1 TB 7200 RPM Stripe Raid – Media Drive
    Windows 7 professional 64 bit
    Tapco Firelink – Audio Interface (Mackie 64 bit Driver version 1.7 for Vista / W7)
    regards,
    John

    The first issue, system freeze while editing, is most likely some sort of hardware or driver conflict.  Audition itself won't be able to do much to the entire computer and OS, but the most likely link will be Auditions use of the audio driver.  Some quick things to check or try:
    Ensure you're using the latest driver from your audio device manufacturer.
    If you're using a native ASIO driver, try switching to MME or vice versa.  This can narrow down the problem, no matter the outcome.  (If the freezes occur with both drivers, it can point to hardware issues.  If it's isolated to one driver model, it points to the driver software.)
    Try temporarily changing your default audio device altogether.  If you're using an external device, try using the built-in options if available.  Or try using a third-party generic driver such as the one found at www.asio4all.com. 
    Note if you're using or enabled any sort of disk-cacheing or speedup utilities.  Sometimes these can introduce bad or unexpected behavior.
    You might want to run a few utilities to scan your hard drives and your RAM for errors or problems.  While I've occasionally managed to track a problem like this down to a driver, more often than not it's been a hard drive or RAM going bad.  Your system looks pretty new, though.  I'm not familiar enough with the Tapco Firelink to offer any specific advice yet.
    For the second issue, the inability to use the crash recovery files, this is likely related to the system freeze.  If Audition crashes, the crash recovery files are usually properly closed by the OS file handler, so that they are more likely to be up-to-date and usable when you launch Audition the next time.  However, in the event of a catastrophic system failure (blue screen, power outage, or completely system freeze like you report) these files are not closed and are usually corrupt which could certainly cause Audition to fail.  I suspect if we can resolve the system lock-up issue, this second issue will not be a problem.

  • Auditing CREATE SESSION WHENEVER UNSUCCESSFUL causes additional audits ?

    Goal is to audit for failed logins. Therefore enabled auditing (we're going to OS, not DB). And "audit create session whenever unssuccessful".
    This does result in audit log files with entries containing "RETURNCODE: "1017" ...which is what was expected. But - we also get NUMEROUS log files with other RETURNCODES which report failures like 6502 (data issues, etc..), and many others. In all cases, the "PRIV$USED" value in the log entry is "5" (which maps to "CREATE SESSION"... but I don't see the relationship/relevance to this being an unsuccessful create session. ? Any thoughts ?
    Here's example:=>
    SESSIONID: "181341776" ENTRYID: "1" STATEMENT: "613" USERID: "APPS" TERMINAL: "unknown" ACTION: "47" RETURNCODE: "6502" OS$USERID: "applprd" PRIV$USED: 5
    User APPS (this is eBusiness) perfoming action 47 (a PLSQL execution) which results in ORA-6502 (numeric or value error). But how is this an unsuccessful "CREATE SESSION" (PRIV$USED=5) ??
    thanks for feedback ... Tom

    Hi -
    Thanks for the feedback...Actually, not sure whether it matters. Both "audit create session whenever not successful" and "audit session whenever not successful" display exactly same in "DBA_STMT_AUDIT_OPTS" and "DBA_PRIV_AUDIT_OPTS" views. I'm really only concerned when create session results in ORA-01017. My real issue - and it may be more an academic question - is that many other failures are reported which have nothing to do with creating a session..but other errors like "ORA-06502", and the audit entry states "PRIV$USED=5" -- just doesn't seem to make sense.
    DB is 9.2.0.7, OS is AIX 5.3.
    Thanks,
    Tom

  • A few questions about auditing

    Hi all,
    I am new to auditing, my manager asked me to make a report on how our database is audited including audit levels, tables and users audited etc. After some research I found about AUD$ table and views associated with it. I also found about table auditing(session/access) but I could not make any clear ideas out of these info. Also I made some tests and I could not get any assuring results. First I want to tell you what I did:
    I enabled auiditing on the fnd_user table(test instance, 9.2.0.8) on select and update using TOAD. However after making many selects and updates I can not find any audit info in either audit trail or AUD$ table and views using it. After this I turned on all other statements'(alter, delete, grant etc.) auditing and switched between ACCESS and SESSION but to no good. What am I missing, why is there no trail of these actions?
    Second, I have been inspecting the AUD$ table, there is recent data in it which consists of drop and truncate info mostly. I used a query to determine which objects have auditing enabled but there are none other than the fnd_user which I just enabled. What makes this data to be populated in the AUD$ table and how can I alter this?
    Lastly, what are the possibilities of efficient auditing on the tables, users and schemas I want?
    Any advices will be most appreciated.
    Thanks and regards
    Burak

    Hi,
    Thanks for the fast replies.
    The output of show parameter audit is:
    NAME TYPE VALUE
    audit_file_dest string ?/rdbms/audit
    audit_sys_operations boolean FALSE
    audit_trail string NONE
    transaction_auditing boolean TRUE
    audit_trail is not boolean, what are the values it can get? transaction_auditing is enabled, how can I make use of this, and what are the differences between the three types of auditing?
    Also I will be very happy if someone could tell me what populates the data in AUD$ table although the auditing is disabled?
    Thanks and regards
    Burak

  • How to audit a user at same time it is created?

    Hi, I got a problem and I hope someone can help me.
    Is there any way of auditing a user at same time it is created?
    For example I create the user "Eddy" and I want this account to be automatically audited so I don't have to execute "audit session username;" each time a new user is created.

    I wasn't aware but it seems that most of DDL operations are not available directly from system triggers. Anyway, you can log the user created in a table (stored in ora_dict_obj_name) for being processed later with a scheduled job.
    All in all, it seems much more easier to use two sentences create + audit.

  • ISE 1.1 - switch ignores "Session-Timeout"

    hi all,
    I'm playing around with ISE guest service and have some difficulty with Time Profiles.
    After guest logs in, Radius attributes are sent to the switch (3750G) one of them is Session-Timeout which should be similar to 1h (DefaultOneHour)
    According to ISE logs and switch debugs, ISE did it well and this attribute was sent  but it seems that the switch simply ignores it.
    May 24 07:03:11.658: %SEC-6-IPACCESSLOGP: list ACL-DEFAULT denied udp 10.1.100.194(1029) -> 10.1.100.2(389), 1 packet19:46:57: RADIUS: COA  received from id 36 10.1.100.6:64700, CoA Request, len 18319:46:57: RADIUS/DECODE: parse unknown cisco vsa "reauthenticate-type" - IGNORE19:46:57: RADIUS/ENCODE(00000000):Orig. component type = Invalid19:46:57: RADIUS(00000000): sending19:46:57: RADIUS(00000000): Send CoA Ack Response to 10.1.100.6:64700 id 36, len 3819:46:57: RADIUS:  authenticator 0B 30 6E 9B DF 97 0D A0 - D9 8B A5 5A 11 39 3E 4119:46:57: RADIUS:  Message-Authenticato[80]  18 19:46:57: RADIUS:   11 42 82 E2 52 68 DF 28 CD 43 AE 88 0C 5D 91 10            [ BRh(C]]19:46:57: RADIUS/ENCODE(00000026):Orig. component type = Dot1X19:46:57: RADIUS(00000026): Config NAS IP: 0.0.0.019:46:57: RADIUS(00000026): Config NAS IPv6: ::19:46:57: RADIUS/ENCODE(00000026): acct_session_id: 2719:46:57: RADIUS(00000026): sending19:46:57: RADIUS/ENCODE: Best Local IP-Address 10.1.100.1 for Radius-Server 10.1.100.619:46:57: RADIUS(00000026): Send Access-Request to 10.1.100.6:1812 id 1645/25, len 26719:46:57: RADIUS:  authenticator 6D 92 DC 77 87 47 DA 8E - 7D 6B DD DD 18 BE DC 3319:46:57: RADIUS:  User-Name           [1]   14  "0016d329042f"19:46:57: RADIUS:  User-Password       [2]   18  *19:46:57: RADIUS:  Service-Type        [6]   6   Call Check                [10]19:46:57: RADIUS:  Vendor, Cisco       [26]  31 19:46:57: RADIUS:   Cisco AVpair       [1]   25  "service-type=Call Check"19:46:57: RADIUS:  Framed-IP-Address   [8]   6   10.1.100.194 19:46:57: RADIUS:  Framed-MTU          [12]  6   1500 19:46:57: RADIUS:  Called-Station-Id   [30]  19  "00-24-F9-2D-83-87"19:46:57: RADIUS:  Calling-Station-Id  [31]  19  "00-16-D3-29-04-2F"19:46:57: RADIUS:  Message-Authenticato[80]  18 19:46:57: RADIUS:   AD EB 99 4A F2 B9 4E BB 2E B3 E2 04 BE 5B 0C 72             [ JN.[r]19:46:57: RADIUS:  EAP-Key-Name        [102] 2   *19:46:57: RADIUS:  Vendor, Cisco       [26]  49 19:46:57: RADIUS:   Cisco AVpair       [1]   43  "audit-session-id=0A01280100000016043E0D23"19:46:57: RADIUS:  NAS-Port-Type       [61]  6   Ethernet                  [15]19:46:57: RADIUS:  NAS-Port            [5]   6   50107 19:46:57: RADIUS:  NAS-Port-Id         [87]  22  "GigabitEthernet1/0/7"19:46:57: RADIUS:  Called-Station-Id   [30]  19  "00-24-F9-2D-83-87"19:46:57: RADIUS:  NAS-IP-Address      [4]   6   10.1.100.1 19:46:57: RADIUS(00000026): Sending a IPv4 Radius Packet19:46:57: RADIUS(00000026): Started 5 sec timeout19:46:57: RADIUS: Received from id 1645/25 10.1.100.6:1812, Access-Accept, len 27219:46:57: RADIUS:  authenticator F1 5F 57 72 FD 80 95 20 - 46 47 B5 CE DF 63 6E 1A19:46:57: RADIUS:  User-Name           [1]   19  "[email protected]"19:46:57: RADIUS:  State               [24]  40 19:46:57: RADIUS:   52 65 61 75 74 68 53 65 73 73 69 6F 6E 3A 30 41  [ReauthSession:0A]19:46:57: RADIUS:   30 31 32 38 30 31 30 30 30 30 30 30 31 36 30 34  [0128010000001604]19:46:57: RADIUS:   33 45 30 44 32 33            [ 3E0D23]19:46:57: RADIUS:  Class               [25]  49 19:46:57: RADIUS:   43 41 43 53 3A 30 41 30 31 32 38 30 31 30 30 30  [CACS:0A012801000]19:46:57: RADIUS:   30 30 30 31 36 30 34 33 45 30 44 32 33 3A 69 73  [00016043E0D23:is]19:46:57: RADIUS:   65 2F 31 32 34 30 33 36 37 39 31 2F 32 39 37   [ e/124036791/297]19:46:57: RADIUS:  Session-Timeout     [27]  6   2940 19:46:57: RADIUS:  Termination-Action  [29]  6   0 19:46:57: RADIUS:  Message-Authenticato[80]  18 19:46:57: RADIUS:   26 46 2C B6 75 95 AF 37 E6 3B B1 CB F2 70 E0 8D           [ &F,u7;p]19:46:57: RADIUS:  Vendor, Cisco       [26]  72 19:46:57: RADIUS:   Cisco AVpair       [1]   66  "ACS:CiscoSecure-Defined-ACL=#ACSACL#-IP-Contractors-ACL-4fbcd736"19:46:57: RADIUS:  Vendor, Cisco       [26]  42 19:46:57: RADIUS:   Cisco AVpair       [1]   36  "profile-name=Microsoft-Workstation"19:46:57: RADIUS(00000026): Received from id 1645/2519:46:57: RADIUS/DECODE: parse unknown cisco vsa "profile-name" - IGNOREMay 24 07:03:19.132: %MAB-5-SUCCESS: Authentication successful for client (0016.d329.042f) on Interface Gi1/0/7 AuditSessionID 0A01280100000016043E0D23May 24 07:03:19.132: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (0016.d329.042f) on Interface Gi1/0/7 AuditSessionID 0A01280100000016043E0D23May 24 07:03:19.140: %EPM-6-POLICY_REQ: IP 10.1.100.194| MAC 0016.d329.042f| AuditSessionID 0A01280100000016043E0D23| AUTHTYPE DOT1X| EVENT APPLYMay 24 07:03:19.165: %EPM-6-AAA: POLICY xACSACLx-IP-Contractors-ACL-4fbcd736| EVENT DOWNLOAD-REQUEST19:46:57: RADIUS/ENCODE(00000000):Orig. component type = Invalid19:46:57: RADIUS(00000000): Config NAS IP: 0.0.0.019:46:57: RADIUS(00000000): sending19:46:57: RADIUS/ENCODE: Best Local IP-Address 10.1.100.1 for Radius-Server 10.1.100.619:46:57: RADIUS(00000000): Send Access-Request to 10.1.100.6:1812 id 1645/26, len 14419:46:57: RADIUS:  authenticator 1A 52 18 C5 25 A7 5C DC - 29 C9 5C 7C C5 B3 FC 5819:46:57: RADIUS:  NAS-IP-Address      [4]   6   10.1.100.1 19:46:57: RADIUS:  User-Name           [1]   38  "#ACSACL#-IP-Contractors-ACL-4fbcd736"19:46:57: RADIUS:  Vendor, Cisco       [26]  32 19:46:57: RADIUS:   Cisco AVpair       [1]   26  "aaa:service=ip_admission"19:46:57: RADIUS:  Vendor, Cisco       [26]  30 19:46:57: RADIUS:   Cisco AVpair       [1]   24  "aaa:event=acl-download"19:46:57: RADIUS:  Message-Authenticato[80]  18 19:46:57: RADIUS:   2B 6B 13 37 0D 25 11 E9 6A 56 35 D8 91 9F EF F0           [ +k7?jV5]19:46:57: RADIUS(00000000): Sending a IPv4 Radius Packet19:46:57: RADIUS(00000000): Started 5 sec timeoutMay 24 07:03:19.191: %SEC-6-IPACCESSLOGP: list ACL-DEFAULT denied tcp 10.1.100.194(2125) -> 10.1.100.6(8443), 1 packet19:46:57: RADIUS: Received from id 1645/26 10.1.100.6:1812, Access-Accept, len 35919:46:57: RADIUS:  authenticator 31 B0 73 93 CA 0E 5C 7C - 11 29 AA 57 6C A1 53 D819:46:57: RADIUS:  User-Name           [1]   38  "#ACSACL#-IP-Contractors-ACL-4fbcd736"19:46:57: RADIUS:  State               [24]  40 19:46:57: RADIUS:   52 65 61 75 74 68 53 65 73 73 69 6F 6E 3A 30 61  [ReauthSession:0a]19:46:57: RADIUS:   30 31 36 34 30 36 30 30 30 30 30 30 35 44 34 46  [0164060000005D4F]19:46:57: RADIUS:   42 44 44 44 33 37            [ BDDD37]19:46:57: RADIUS:  Class               [25]  49 19:46:57: RADIUS:   43 41 43 53 3A 30 61 30 31 36 34 30 36 30 30 30  [CACS:0a016406000]19:46:57: RADIUS:   30 30 30 35 44 34 46 42 44 44 44 33 37 3A 69 73  [0005D4FBDDD37:is]19:46:57: RADIUS:   65 2F 31 32 34 30 33 36 37 39 31 2F 32 39 38   [ e/124036791/298]19:46:57: RADIUS:  Termination-Action  [29]  6   1 19:46:57: RADIUS:  Message-Authenticato[80]  18 19:46:57: RADIUS:   80 EF 5B 80 76 F1 C9 37 0B 25 34 37 10 57 CC 44          [ [v7?47WD]19:46:57: RADIUS:  Vendor, Cisco       [26]  47 19:46:57: RADIUS:   Cisco AVpair       [1]   41  "ip:inacl#1=permit udp any any eq domain"19:46:57: RADIUS:  Vendor, Cisco SW3750-1# [26]  48 19:46:57: RADIUS:   Cisco AVpair       [1]   42  "ip:inacl#2=permit ip any host 10.1.100.6"19:46:57: RADIUS:  Vendor, Cisco       [26]  57 19:46:57: RADIUS:   Cisco AVpair       [1]   51  "ip:inacl#3=deny ip any 10.0.0.0 0.255.255.255 log"19:46:57: RADIUS:  Vendor, Cisco       [26]  36 19:46:57: RADIUS:   Cisco AVpair       [1]   30  "ip:inacl#4=permit ip any any"19:46:57: RADIUS(00000000): Received from id 1645/26May 24 07:03:19.216: %EPM-6-AAA: POLICY xACSACLx-IP-Contractors-ACSW3750-1#SW3750-1#SW3750-1#L-4fbcd736| EVENT DOWNLOAD-SUCCESSMay 24 07:03:19.216: %EPM-6-POLICY_APP_SUCCESS: IP 10.1.100.194| MAC 0016.d329.042f| AuditSessionID 0A01280100000016043E0D23| AUTHTYPE DOT1X| POLICY_TYPE Named ACL| POLICY_NAME xACSACLx-IP-Contractors-ACL-4fbcd736| RESULT SUCCESSMay 24 07:03:20.147: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0016.d329.042f) on Interface Gi1/0/7 AuditSessionID 0A01280100000016043E0D2319:46:58: RADIUS/ENCODE(00000026):Orig. component type = Dot1X19:46:58: RADIUS(00000026SW3750-1#SW3750-1#SW3750-1#SW3750-1#): Config NAS IP: 0.0.0.019:46:58: RADIUS(00000026): Config NAS IPv6: ::19:46:58: RADIUS/ENCODE: Best Local IP-Address 10.1.100.1 for Radius-Server 10.1.100.619:46:58: RADIUS(00000026): Sending a IPv4 Radius Packet19:46:58: RADIUS(00000026): Started 5 sec timeout19:46:58: RADIUS: Received from id 1646/35 10.1.100.6:1813, Accounting-response, len 38SW3750-1#
    SW3750-1#sh authe sess int g 1/0/7 Interface:  GigabitEthernet1/0/7 MAC Address:  0016.d329.042f IP Address:  10.1.100.194 User-Name:  [email protected] Status:  Authz Success Domain:  DATA Security Policy:  Should Secure Security Status:  Unsecure Oper host mode:  multi-auth Oper control dir:  both Authorized By:  Authentication Server Vlan Group:  N/A ACS ACL:  xACSACLx-IP-Contractors-ACL-4fbcd736 Session timeout:  N/A Idle timeout:  N/A Common Session ID:  0A01280100000016043E0D23 Acct Session ID:  0x0000001B Handle:  0x2F000017Runnable methods list: Method   State mab      Authc Success dot1x    Not runSW3750-1#
    Has anyone encountered similar thing?
    I tried 12.2(58) and now Im testing
    Cisco IOS Software, C3750 Software (C3750-IPSERVICESK9-M), Version 15.0(1)SE2, RELEASE SOFTWARE (fc3)
    but in both cases it is similar.
    regards
    Przemek

    Hi Sebastian,
    thx a lot those 2 commands solved the issue, my mistake. Now I can see remaining time for the session
    SW3750-1#sh auth sess int g1/0/7 Interface:  GigabitEthernet1/0/7 MAC Address:  0016.d329.042f IP Address:  10.1.100.194 User-Name:  [email protected] Status:  Authz Success Domain:  DATA Security Policy:  Should Secure Security Status:  Unsecure Oper host mode:  multi-auth Oper control dir:  both Authorized By:  Authentication Server Vlan Group:  N/A ACS ACL:  xACSACLx-IP-Contractors-ACL-4fbcd736 Session timeout:  28800s (server), Remaining: 28780s Timeout action:  Terminate Idle timeout:  N/A Common Session ID:  0A012801000000221DE0F555 Acct Session ID:  0x0000002B Handle:  0x99000023Runnable methods list: Method   State mab      Authc Success dot1x    Not run
    regards
    Przemek

  • Active users and connections in v$session

    How can I write an SQL script or query to find the following :
    1. The total number of times a user called BRIGG connects to the database in a day(24 hour period)
    2. The STATUS in V$SESSION could be ACTIVE or INACTIVE. I needed to track as to how many times, the user BRIGG was ACTIVE on a given day(24 hour period)
    Thanks

    1.
    You can audit user logons with the database trigger and then run sql over your own audit table (http://www.dba-oracle.com/art_builder_sec_audit.htm)
    or
    you can use oracle audit trail (http://download-west.oracle.com/docs/cd/B10501_01/server.920/a96521/audit.htm#1108)
    to audit brigg's session using
    audit session by brigg;
    Check out this article - http://www.securityfocus.com/infocus/1689
    2. I don't think there is straightforward way to do it. You can wite the procedure or script to
    select sysdate,status,username from v$session where username ='BRIGG' ;
    run it at desired interval (i.e every second) and capture the output in the table for the later analysis.
    What are you trying to achive by 2? I don't see a lot of sense in monitoring ACTIVE/INACTIVE status of the session - what kind of infromation are you trying to extract from it? May be there is another way ...
    Mike

  • Manage AUDIT using  different user

    Dear Friends ,
    I have to run audit trail in my production database which only gathered user session related information . I just run following two lines as 'SYS' user :
    SQL> conn sys/password as sysdba
    SQL> audit session whenever successful;
    Audit succeeded.
    SQL> audit session whenever not successful;
    Audit succeeded.
    Now, I get all audit related information in AUD$ table as SYS user . But I dont want to use AUD$ table in system tablespace .
    Instead of using the AUD$ table , I like to use a different user like AUDIT1 (which is created in different tablespace) who holds a different table like AUD$ and also keeps all the session realted information like AUD$ table . Is it possible to do ?
    Plz inform me .. ..

    Shipon,
    If you are going to make auditing via Database than the records will go in AUD$ table only. There is a metalink note that talks about the movement of AUD$ to another tablespace and also for related objects. You may want to check that note,*Metalink notes 72460.1 "Moving AUD$ to Another Tablespace and Adding Triggers to AUD$" and 1019377.6: "Script to move SYS.AUD$ table out of SYSTEM tablespace".*
    On the other hand, you may want to look around for other options to enable Auditing, for example, o/s based.
    HTH
    Aman....

  • Audition Import / Export to/from other DAWs

    Well its done!
    AATranslator is finally finished.
    http://www.aatranslator.com.au/ is where you will find it.
    Its been 3 months in the making and as I mentioned previously its not donationware but it is a fully functional demo only limitation is the number of tracks and 'clips'.
    Many thanks to John Lundsten from  the UK for the idea of this project, for his tireless efforts testing the application and for his insight as well as the user guide.  Thanks also to Adrian Connelly for additional programming efforts and the interface and also dstDean from this forum for additional testing and encouragement.
    Those who have supported me in the past (as at the time of this post) through donating for any of my previous applications are entitled to $50usd off the price for every application they have donated to me in the past.  For some that equals a free copy!  Never let it be said that I don't appreciate your support!
    This application is not for everyone but certainly for anyone who needs to move their projects from one DAW to another it is certainly worth a look.
    It definitely the only application which currently allows you to import/export from Adobe Audition!
    There are many other DAWS in our sights and significant work has already been completed interfacing to Reaper project files and OpenTL files.  These will appear in a free upgrade in the not too distant future.
    Enjoy.....

    Welcome aboard!
    There are a number of points to address here:-
    "I presume there is no back up facility for your Adobe Audition® session file like Premier Pro has with Auto Save."
    That is correct but even with applications with 'auto save' there is no substitute for regular backup of both your audio files, session file & audition settings.
    "To fix this problem I was thinking about SESBackup (Donate) so this never happens again. Does the product work like the auto save facility in PRO (i.e. the session) or does it record & save everything i.e. the sound files again as well into a specific folder of your choice."
    SESBackup only targets adobe session files (either singularly or ALL of your session files).  It is handy to easily back them (or it) up before recommencing work on a project or as soon as you are finished for the day.  It does not backup your audio material.
    MediaSweeper will isolate and seperate the unused files from your project and move them to another location so that you only backup the material that is actually in your session.
    AuditionFX will help you backup your Adobe Audition settings
    "More importantly I need to combine these two sessions together and presume there is no facility for you to do this Adobe as well."
    As I recall AA1.5 has the facility to 'append' other AA1.5 sessions.
    "I have just read this thread and I am hoping AATranslator can achieve this. If translator does do this what is the best way to achieve a great result without losing any information."
    As far as Audition is concerned AAtranslator was designed with AA3 in mind.  AATranslator can append sessions either from Audition, Samplitude, Cubase, Nuendo, Reaper, etc but it would need to be converted to an AA3 xml file at present.
    But as i mentioned before AA1.5 it (as I recall) has that 'append' function built in.
    Remember "save early and save often".
    BTW You can download and try all of those applications and they all come with documentation.

  • Auditing in oracle 10g database and oracle 10g application server

    Dear friends,
    We have oracle 10g application server and oracle 10g database server in place.My criteria is to audit users connected using oracle application user credentials to the database.
    Can you please tell me how can i do it.
    Thanks & regards,

    Its the database connection you want to track. The session audit will show where it came from.
    Auditing is turned using this command:
    alter system set audit_trail = DB scope=spfile;
    Note: The use of spfile will require a DB bounce before audit starts
    To audit Sessions:
    audit create session;
    Query by Audit Type:
    SELECT A.USERNAME,
    OS_USERNAME,
    A.TIMESTAMP,
    A.RETURNCODE,
    TERMINAL,
    USERHOST
    FROM DBA_AUDIT_SESSION A
    WHERE USERHOST = <replace with iAS servername> ;
    By User
    SELECT USERNAME,OBJ_NAME,ACTION_NAME , TIMESTAMP
    FROM DBA_AUDIT_TRAIL WHERE USERNAME = 'SCOTT';
    Check for users sharing database accounts
    select count(distinct(terminal)),username
    from dba_audit_session
    having count(distinct(terminal))>1
    group by username;
    Attempts to access the database at unusual hours
    SELECT username, terminal, action_name, returncode,
    TO_CHAR (TIMESTAMP, 'DD-MON-YYYY HH24:MI:SS'),
    TO_CHAR (logoff_time, 'DD-MON-YYYY HH24:MI:SS')
    FROM dba_audit_session
    WHERE TO_DATE (TO_CHAR (TIMESTAMP, 'HH24:MI:SS'), 'HH24:MI:SS') <
    TO_DATE ('08:00:00', 'HH24:MI:SS')
    OR TO_DATE (TO_CHAR (TIMESTAMP, 'HH24:MI:SS'), 'HH24:MI:SS') >
    TO_DATE ('19:30:00', 'HH24:MI:SS');
    Attempts to access the database with non-existent users
    SELECT username, terminal, TO_CHAR (TIMESTAMP, 'DD-MON-YYYY HH24:MI:SS')
    FROM dba_audit_session
    WHERE returncode <> 0
    AND NOT EXISTS (SELECT 'x'
    FROM dba_users
    WHERE dba_users.username = dba_audit_session.username);
    Other audits you might consider:
    audit grant any object privilege;
    audit alter user;
    audit create user;
    audit drop user;
    audit drop tablespace;
    audit grant any role;
    audit grant any privilege;
    audit alter system;
    audit alter session;
    audit delete on AUD$ by access;
    audit insert on AUD$ by access;
    audit update on AUD$ by access;
    audit delete table;
    audit create tablespace;
    audit alter database;
    audit create role;
    audit create table;
    audit alter any procedure;
    audit create view;
    audit drop any procedure;
    audit drop profile;
    audit alter profile;
    audit alter any table;
    audit create public database link;
    Best Regards
    mseberg

Maybe you are looking for

  • Scanning from Photosmart 4580 to Macbook Pro

    Hi, whilst I can print documents from the Mac I cannot scan from the Photosmart to the Mac. On System Preferences under Printers and Scanners there is no scan option. Can you help please? Thanks

  • Balance Carry-Forward Problem for Subledger Accounts

    Hi Experts, We are doing the Balance Carry-Forward this Year 2012 and we are having problems with the amount to be carry-over of AP/AR Subledgers for this year. We checked the C/F Balance for G/L and there are no problems. When I go to tables KNC1 or

  • Mounting Cdrom Drive In Guest Domain running 1.0.3

    Folks, I have followed the Admin guide on how to export Cdrom/Dvd drive from Service Domain to Guest Domain, however once allocated to the guest domain we are unable to mount the device. Any help is appreciated. Here are my bindings ldm list-bindings

  • Can applet pass value back to web page?

    if i run an applet in a web page, eg: aspx is it possible for me to pass value back to the page?

  • How to keep two libraries synchronized ?

    I recently bought a laptop which I am going to use beside my regular PC. I installed iTunes on both PC's, but here comes the problem: those are not the same libraries. I of course could copy them once and it will look like they are the same, but in f