SQL> conn / as sysdba;
SQL> show parameter audit;
NAME TYPE VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest string /u01/app/oracle/admin/ORCL/adump
audit_sys_operations boolean FALSE
audit_syslog_level string
audit_trail string NONE
#####//SQL> alter system set audit_sys_operations=TRUE scope=spfile; --审计管理用户(以sysdba/sysoper角色登陆)//俺不执行这句
SQL> alter system set audit_trail=db,extended scope=spfile;
SQL> startup force;
SQL> show parameter audit;
NAME TYPE VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest string /u01/app/oracle/admin/ORCL/adump
audit_sys_operations boolean TRUE
audit_syslog_level string
audit_trail string DB, EXTENDED
########开始审计
SQL> conn / as sysdba
SQL> audit update table,insert table by pdm9;
SQL> startup force;
##查看审计
SQL> select OS_USERNAME,username,USERHOST,TERMINAL,TIMESTAMP,OWNER,obj_name,ACTION_NAME,sessionid,os_process,sql_text from dba_audit_trail;
##关闭审计
SQL>alter system set audit_trail='FALSE' scope=spfile;
SQL> startup force;
入门文章:
[url]http://www.securityfocus.com/infocus/1689[/url]
[url]http://www.petefinnigan.com/[/url]
1193

被折叠的 条评论
为什么被折叠?



