Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Oracle on AIX issues

    Posted 9 days ago

    Dear team,

    I am testing Oracle built on AIX system. But i have some issues with it.

    • Cannot see UserDB: it shows "connected user" only
    • Cannot see OS users, OS host or more information details in alert/violation.
    • How can i get a troubleshooting log?

    Does anyone have solutions for them?


    #DatabaseActivityMonitoring

    ------------------------------
    Duc Dinh Minh
    Security Engineer I
    M.Tech Holdings Pte Ltd
    ho chi minh
    ------------------------------


  • 2.  RE: Oracle on AIX issues

    Posted 8 days ago

    I am also interested in the solution as i experience the same issues too



    ------------------------------
    Juliet Ehichioya
    Security Engineer
    Keystone Bank Limited
    Lagos
    ------------------------------



  • 3.  RE: Oracle on AIX issues

    Posted 7 days ago

    Hi,

    "Connected User" in DB audit data means "Untraceable Database User", this violation is invoked if On-Premises (SecureSphere) is unable to identify the database user.

    This can happen, for example:

    1. If a session was opened before a newly-deployed gateway came online, or a session was opened just before a gateway came online in fail-over mode.

    2. "Old" connection - stream is a long stream that was started x hours ago (more than 2 hours) and wasn't active for a period of time, and after a while it became active again.

    Within On-Premises (SecureSphere) there is definition per service about connection timeout (default: 7200 seconds -> 2 hours) after this period On-Premises (SecureSphere) removes connection details. If this session (between client and server) is used after 2 hours – On-Premises (SecureSphere) will not see the SYN, SYN/ACK, and will indicate the user is connected user, but since no information about this session is available will mark it as untraceable user.

    Note: Do not increase the default value of "connection timeout" without specific instructions from Support, since this will increase gateway memory consumption.

    3. Gateway missed traffic due to CPU Load / Heavy traffic / Network gaps / Sniffing mode without TAP device

    You need to know that after agent installation on AIX + ORACLE, you must restart Oracle services.

    https://docs.imperva.com/bundle/v14.18-dam-administration-guide/page/7349.htm

    If you have installed the SecureSphere Agent on a machine on which no SecureSphere Agent was previously installed, then:

    • You must restart all database instances and processes after the first time you start the SecureSphere Agent. For example, in Oracle, the "tnslsnr" process should also be restarted.
    • If you ever manually enabled EIK, you must restart the database for every agent reinstallation.
    • If you want to enable the source IP address feature, you must restart the login servers (SSH, Telnet, Rlogin) after the first time you start the SecureSphere Agent.

    There is no need to reboot the machine.



    ------------------------------
    Karol Gruszczynski
    IT Security Expert
    Trafford IT Sp. z o.o.
    Warszawa
    ------------------------------



  • 4.  RE: Oracle on AIX issues

    Posted 6 days ago
    Edited by Duc Dinh Minh 6 days ago

    I checked violations/ Alerts,

    It can get information if users are local,

    But with remote users, we can see query, but dont have databases & schema, user, db application information ...

    I added the below to agent advance configuration, but still not work:

    <external-traffic-monitoring-in-kern>1</external-traffic-monitoring-in-kern>
    <enable-oracle-aso>true</enable-oracle-aso>



    ------------------------------
    Duc Dinh Minh
    Security Engineer I
    M.Tech Holdings Pte Ltd
    ho chi minh
    ------------------------------



  • 5.  RE: Oracle on AIX issues

    Posted 6 days ago

    Hi,

    You may refer to the link (https://docs.imperva.com/bundle/z-kb-articles-knowledgebase-support/page/290589741.html) or to the detailed response provided by Imperva Partner.

    Also, please ensure that the latest version of agent is being used to monitor the activities performed on Oracle database installed on AIX server and to monitor ASO connections, one has to add flag in the advanced configurations as per Imperva's documentation: https://docs.imperva.com/bundle/v14.18-dam-user-guide/page/77566.htm

    Regards,



    ------------------------------
    SBISOC 4430
    Manager
    Mumbai
    ------------------------------