Audit Autonomous AI Database

Autonomous AI Database provides auditing that allows you to monitor Oracle AI Database activities.

About Auditing Autonomous AI Database

Autonomous AI Database provides auditing to track, monitor, and record database actions. Auditing can help you detect security risks and improve regulatory compliance for your database.

Audit Features on Autonomous AI Database

Autonomous AI Database includes extensive, sophisticated audit capabilities that allow you capture the audit information you need for your organization. Autonomous AI Database provides default auditing.

In addition, you can use either of the following to apply auditing policies:

You can configure auditing to accomplish the following:

Audit Data on Autonomous AI Database

Autonomous AI Database protects audit data and writes its audit trail to the UNIFIED_AUDIT_TRAIL data dictionary view.

The underlying table storing audit data on Autonomous AI Database is AUDSYS.AUD$UNIFIED. This table is protected and does not allow users to perform DML/DDL operations or to purge the table (any attempt to perform these actions automatically produces an audit record). After an audit record is written, the only activity allowed is for the ADMIN user to perform a PURGE. The ADMIN has the AUDIT_ADMIN role that is required to run a PURGE. If you assign the AUDIT_ADMIN role to another user, then that user could also perform a PURGE.

Depending on the number and type of audit policies you use and the amount of activity, over time the audit trail can grow to use a large amount of storage. Autonomous AI Database provides the following ways to limit the storage required for audit data:

If you need a longer audit data retention period than 14 days, use Oracle Data Safe to retain audit data. See Extend Audit Record Retention with Oracle Data Safe on Autonomous AI Database for more information.

Autonomous AI Database audits and logs every operation carried out in your database by the Oracle Cloud Infrastructure Operations teams. See View Oracle Cloud Infrastructure Operations Actions for more information on how to audit Operations activities.

Default Audit Policies on Autonomous AI Database

Autonomous AI Database provides auditing to track, monitor, and record activities on your database.

By default, Autonomous AI Database applies audit policies to audit the following database activities:

In addition, you can use either of the following to apply additional auditing policies:

Register Oracle Data Safe on Autonomous AI Database

Use Oracle Data Safe to apply auditing policies for database users, for administrative users, to apply predefined auditing policies or to extend the audit data record retention for your Autonomous AI Database instance.

Register your Autonomous AI Database instance with Oracle Data Safe as follows:

  1. Access your Autonomous AI Database instance from the Oracle Cloud Infrastructure Console.

    1. Open the Oracle Cloud Infrastructure Console by clicking the navigation icon next to Oracle Cloud.

    2. From the Oracle Cloud Infrastructure left navigation menu click Oracle AI Database and then click Autonomous AI Database.

    3. On the Autonomous AI Databases page select an Autonomous AI Database from the links under the Display Name column.

  2. Register your Autonomous AI Database instance with Oracle Data Safe.

    1. On the Autonomous AI Database Details page, under Data Safe, click Register.

      Description of image follows

      Description of the illustration adb_data_safe_register.png

    2. In the Register database with Data Safe dialog, click Confirm.

    The Data Safe status shows: Registering. This step takes about 15 to 20 minutes.

After Oracle Data Safe is registered, the Data Safe status shows Registered and two links: View and Deregister.

Click View to show the Data Safe register database details page.

Click Deregister to disable Oracle Data Safe.

Extend Audit Record Retention with Oracle Data Safe on Autonomous AI Database

Use Oracle Data Safe to extend the audit data record retention to a specified number of months.

First register your Autonomous AI Database instance with Oracle Data Safe. See Register Oracle Data Safe on Autonomous AI Database for more information.

After your Autonomous AI Database instance is registered, you can specify the Data Safe retention period.

See Update Retention Periods for a Target Database for more information.

View and Manage Oracle Data Safe Audit Trails on Autonomous AI Database

Data Safe uses audit trails to define where to retrieve the audit data and to collect Autonomous AI Database audit records. During the registration process, Oracle Data Safe discovers the audit trails and creates an audit trail resource.

Oracle Data Safe lists resources on the Audit Trails page. To access the Audit Trails page, under Security Center in Data Safe click Activity Auditing, and then, on the Activity Auditing page under Related Resources click Audit Trails. You can discover new audit trails at any time and remove audit trail resources in Oracle Data Safe as needed.

First register your Autonomous AI Database instance with Oracle Data Safe. See Register Oracle Data Safe on Autonomous AI Database for more information.

When the Autonomous AI Database is stopped or restarted, the following happens:

You can also manually stop or delete the audit trail. Deleting the audit trail does not remove audit records that have already been collected. Those records remain in Data Safe until the retention period is reached.

See View and Manage Audit Trails for more information.

View and Manage Audit Policies with Oracle Data Safe on Autonomous AI Database

Use Oracle Data Safe to set audit policies for your Autonomous AI Database instance.

First register your Autonomous AI Database instance with Oracle Data Safe. See Register Oracle Data Safe on Autonomous AI Database for more information.

After your Autonomous AI Database instance is registered, access Oracle Data Safe to set audit policies.

See View and Manage Audit Policies for more information.

Generate Audit Reports with Data Safe on Autonomous AI Database

Data Safe includes out-of-box audit data reports, and you can create custom reports to suit your needs.

After you enable and register Oracle Data Safe, and you add a trail to collect audit data from your Autonomous AI Database instance, then you can use the reports to monitor activity for your database.

See View and Manage Audit Reports for more information.