{
  "date": "2017-06-04T16:03:04",
  "slug": "12cr2-auditing-all-users-with-a-role-granted",
  "link": "https://www.dbi-services.com/blog/12cr2-auditing-all-users-with-a-role-granted/",
  "title": {
    "rendered": "12cR2 auditing all users with a role granted"
  },
  "content": {
    "rendered": "<h2>By Franck Pachot</h2>\n<p>.<br />\n12.1 introduced Unified Auditing where you define policies and then enable them. As with the traditional audit, you enable them for all users or for specific users. The unified auditing adds a syntax to audit all users except some listed ones. 12.2 adds a syntax to audit a group of users, defined by the role granted. This is the best way to enable a policy for a group of users, including those created later.<br />\n<!--more--><br />\nI create a simple policy, to audit logon and DBA role usage:</p>\n<pre><code>\nSQL&gt; create audit policy DEMO_POLICY actions logon, roles DBA;\nAudit POLICY created.\n</code></pre>\n<p>I create a new DBA user, USER1</p>\n<pre><code>\nSQL&gt; create user USER1 identified by covfefe quota unlimited on USERS;\nUser USER1 created.\nSQL&gt; grant DBA to USER1;\nGrant succeeded.\n</code></pre>\n<p>I want to enable the policy for this user because I want to audit all DBAs</p>\n<pre><code>\nSQL&gt; audit policy DEMO_POLICY by USER1;\nAudit succeeded.\n</code></pre>\n<p>I remove Audit records for this demo</p>\n<pre><code>\nSQL&gt; exec dbms_audit_mgmt.clean_audit_trail(audit_trail_type=&gt;dbms_audit_mgmt.audit_trail_unified,use_last_arch_timestamp=&gt;false);\nPL/SQL procedure successfully completed.\n</code></pre>\n<p>Let&#8217;s connect with this user and see what is audited:</p>\n<pre><code>\nSQL&gt; connect USER1/covfefe@//localhost/PDB1\nConnected.\n&nbsp;\nSQL&gt; select audit_type,os_username,userhost,terminal,dbusername,action_name,unified_audit_policies,system_privilege_used,event_timestamp\n  2   from unified_audit_trail where unified_audit_policies='DEMO_POLICY' order by event_timestamp;\n&nbsp;\nAUDIT_TYPE  OS_USERNAME  USERHOST  TERMINAL  DBUSERNAME  ACTION_NAME  UNIFIED_AUDIT_POLICIES  SYSTEM_PRIVILEGE_USED  EVENT_TIMESTAMP\n----------  -----------  --------  --------  ----------  -----------  ----------------------  ---------------------  ---------------\nStandard    oracle       VM104     pts/0     USER1       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.22.51.865094000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.22.51.948187000 PM\n</code></pre>\n<p>The logon and the select on dictionary table (possible here thanks to the DBA role) has been audited because the policy is enabled for this user.</p>\n<p>We have a new DBA and we create a new user for him:</p>\n<pre><code>\nSQL&gt; create user USER2 identified by covfefe quota unlimited on USERS;\nUser USER2 created.\nSQL&gt; grant DBA to USER2;\nGrant succeeded.\n</code></pre>\n<p>He connects and check what is audited:</p>\n<pre><code>\nSQL&gt; connect USER2/covfefe@//localhost/PDB1\nConnected.\nSQL&gt; select audit_type,os_username,userhost,terminal,dbusername,action_name,unified_audit_policies,system_privilege_used,event_timestamp\n  2   from unified_audit_trail where unified_audit_policies='DEMO_POLICY' order by event_timestamp;\n&nbsp;\nAUDIT_TYPE  OS_USERNAME  USERHOST  TERMINAL  DBUSERNAME  ACTION_NAME  UNIFIED_AUDIT_POLICIES  SYSTEM_PRIVILEGE_USED  EVENT_TIMESTAMP\n----------  -----------  --------  --------  ----------  -----------  ----------------------  ---------------------  ---------------\nStandard    oracle       VM104     pts/0     USER1       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.22.51.865094000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.22.51.948187000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.22.52.132814000 PM\n</code></pre>\n<p>Nothing is audited for this user. The DBA role usage is audited, but only for USER1.</p>\n<p>Of course, we can add an audit statement for each user created for a DBA:</p>\n<pre><code>\nSQL&gt; audit policy DEMO_POLICY by USER2;\nAudit succeeded.\n</code></pre>\n<p>Then his new activity is audited:</p>\n<pre><code>\nSQL&gt; connect USER2/covfefe@//localhost/PDB1\nConnected.\nSQL&gt; select audit_type,os_username,userhost,terminal,dbusername,action_name,unified_audit_policies,system_privilege_used,event_timestamp\n  2   from unified_audit_trail where unified_audit_policies='DEMO_POLICY' order by event_timestamp;\n&nbsp;\nAUDIT_TYPE  OS_USERNAME  USERHOST  TERMINAL  DBUSERNAME  ACTION_NAME  UNIFIED_AUDIT_POLICIES  SYSTEM_PRIVILEGE_USED  EVENT_TIMESTAMP\n----------  -----------  --------  --------  ----------  -----------  ----------------------  ---------------------  ---------------\nStandard    oracle       VM104     pts/0     USER1       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.22.51.865094000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.22.51.948187000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.22.52.132814000 PM\nStandard    oracle       VM104     pts/0     USER2       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.22.52.338928000 PM\n</code></pre>\n<p>But for security reason, we would like to be sure that any new user having the DBA role granted is audited.<br />\nLet&#8217;s try something else</p>\n<pre><code>\nSQL&gt; noaudit policy DEMO_POLICY by USER1,USER2;\nNoaudit succeeded.\n</code></pre>\n<p>We can simply audit all users:</p>\n<pre><code>\nSQL&gt; audit policy DEMO_POLICY;\nAudit succeeded.\n</code></pre>\n<p>But this is too much. Some applications constantly logon and logoff and we don&#8217;t want to have that in the audit trail.</p>\n<pre><code>\nSQL&gt; noaudit policy DEMO_POLICY;\nNoaudit succeeded.\n</code></pre>\n<p>We can still enable the policy for all users, and exempt those users we don&#8217;t want:</p>\n<pre><code>\nSQL&gt; audit policy DEMO_POLICY except DEMO;\nAudit succeeded.\n</code></pre>\n<p>Here is what is enabled, and this will audot all new users:</p>\n<pre><code>\nSQL&gt; select * from audit_unified_enabled_policies;\n&nbsp;\nUSER_NAME  POLICY_NAME         ENABLED_OPT  ENABLED_OPTION  ENTITY_NAME  ENTITY_TYPE  SUCCESS  FAILURE\n---------  -----------         -----------  --------------  -----------  -----------  -------  -------\nDEMO       DEMO_POLICY         EXCEPT       EXCEPT USER     DEMO         USER         YES      YES\nALL USERS  ORA_SECURECONFIG    BY           BY USER         ALL USERS    USER         YES      YES\nALL USERS  ORA_LOGON_FAILURES  BY           BY USER         ALL USERS    USER         NO       YES\n</code></pre>\n<p>But once again, this is not what we want.</p>\n<pre><code>\nSQL&gt; noaudit policy DEMO_POLICY by DEMO;\nNoaudit succeeded.\n&nbsp;\nSQL&gt; select * from audit_unified_enabled_policies;\n&nbsp;\nUSER_NAME  POLICY_NAME         ENABLED_OPT  ENABLED_OPTION  ENTITY_NAME  ENTITY_TYPE  SUCCESS  FAILURE\n---------  -----------         -----------  --------------  -----------  -----------  -------  -------\nALL USERS  ORA_SECURECONFIG    BY           BY USER         ALL USERS    USER         YES      YES\nALL USERS  ORA_LOGON_FAILURES  BY           BY USER         ALL USERS    USER         NO       YES\n</code></pre>\n<h3>Audit all users to whom roles are granted directly</h3>\n<p>In 12<i>c</i>R2 we have the possibility to do exactly what we want: audit all users having the DBA role granted:</p>\n<pre><code>\nSQL&gt; audit policy DEMO_POLICY by users with granted roles DBA;\nAudit succeeded.\n</code></pre>\n<p>This enables the audit for all users for whom the DBA role has been directly granted:</p>\n<pre><code>\nSQL&gt; select * from audit_unified_enabled_policies;\n&nbsp;\nUSER_NAME  POLICY_NAME         ENABLED_OPT  ENABLED_OPTION   ENTITY_NAME  ENTITY_TYPE  SUCCESS  FAILURE\n---------  -----------         -----------  --------------   -----------  -----------  -------  -------\n           DEMO_POLICY         INVALID      BY GRANTED ROLE  DBA          ROLE         YES      YES\nALL USERS  ORA_SECURECONFIG    BY           BY USER          ALL USERS    USER         YES      YES\nALL USERS  ORA_LOGON_FAILURES  BY           BY USER          ALL USERS    USER         NO       YES\n</code></pre>\n<p>The important thing is that a newly created user will be audited as long as he has the DBA role directly granted:</p>\n<pre><code>\nSQL&gt; create user USER3 identified by covfefe quota unlimited on USERS;\nUser USER3 created.\nSQL&gt; grant DBA to USER3;\nGrant succeeded.\n&nbsp;\nSQL&gt; connect USER3/covfefe@//localhost/PDB1\nConnected.\nSQL&gt; select audit_type,os_username,userhost,terminal,dbusername,action_name,unified_audit_policies,system_privilege_used,event_timestamp\n  2   from unified_audit_trail where unified_audit_policies='DEMO_POLICY' order by event_timestamp;\n&nbsp;\nAUDIT_TYPE  OS_USERNAME  USERHOST  TERMINAL  DBUSERNAME  ACTION_NAME  UNIFIED_AUDIT_POLICIES  SYSTEM_PRIVILEGE_USED  EVENT_TIMESTAMP\n----------  -----------  --------  --------  ----------  -----------  ----------------------  ---------------------  ---------------\nStandard    oracle       VM104     pts/0     USER1       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.29.17.915217000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.29.17.988151000 PM\nStandard    oracle       VM104     pts/0     USER1       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.29.18.117258000 PM\nStandard    oracle       VM104     pts/0     USER2       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.29.18.322716000 PM\nStandard    oracle       VM104     pts/0     USER2       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.29.18.345351000 PM\nStandard    oracle       VM104     pts/0     USER2       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.29.18.415117000 PM\nStandard    oracle       VM104     pts/0     USER2       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.29.18.439656000 PM\nStandard    oracle       VM104     pts/0     USER2       SELECT       DEMO_POLICY             SELECT ANY DICTIONARY  04-JUN-17 04.29.18.455274000 PM\nStandard    oracle       VM104     pts/0     USER3       LOGON        DEMO_POLICY             CREATE SESSION         04-JUN-17 04.29.18.507496000 PM\n</code></pre>\n<p>This policy applies to all users having the DBA role, and gives the possibility to audit more than their DBA role usage: here I audit all login from users having the DBA role. </p>\n<h3>So what?</h3>\n<p>We don&#8217;t use roles only to group privileges to grant. A role is usually granted to define groups of users: DBAs, Application user, Read-only application users, etc. The Unified Auditing can define complex policies, combining the audit of actions, privileges, and roles. The 12.2 syntax allows enabling the policy to a specific group of users.</p>\n",
    "protected": false
  }
}
