Table of Contents
- Title and Copyright Information
- Preface
- Changes in Oracle AVDF
-
1
Overview of Oracle Audit Vault and Database Firewall Installation
- 1.1 Learning About Oracle Audit Vault and Database Firewall
-
1.2
Platform Support
-
1.2.1
Product Compatibility Matrix
- 1.2.1.1 Supported Hardware
- 1.2.1.2 Supported Virtualization Platforms
- 1.2.1.3 Audit Collection and Database Firewall Support for Databases
- 1.2.1.4 Audit Collection Support for Operating Systems
- 1.2.1.5 Audit Collection Support for Directory Services
- 1.2.1.6 Audit Collection Support for File Systems
- 1.2.1.7 Supported Operating Systems for Audit Vault Agent and Host Monitor Agent
- 1.2.1.8 Support for Transaction Log Audit Collection Using Oracle GoldenGate
- 1.2.2 Supported Browsers
- 1.2.3 Support for External Systems
- 1.2.4 Audit Vault Agent: Supported and Tested Java Runtime Environment
- 1.2.5 Compatibility with Oracle Enterprise Manager
-
1.2.1
Product Compatibility Matrix
-
2
Oracle Audit Vault and Database Firewall Pre-Install Requirements
- 2.1 Oracle AVDF Deployment Checklist
- 2.2 Oracle Audit Vault and Database Firewall Hardware Requirements
- 2.3 Oracle Audit Vault and Database Firewall Software Requirements
- 2.4 Installing Audit Vault Server on VMware
- 2.5 Privileges Required to Install Oracle Audit Vault and Database Firewall
- 2.6 Audit Vault Agent Requirements
- 2.7 Host Monitor Agent Requirements
- 3 Downloading and Installing Oracle Audit Vault and Database Firewall
-
4
Post-Install Configuration Tasks
- 4.1 Audit Vault Server Post-Installation Tasks
- 4.2 Database Firewall Post-Installation Tasks
- 4.3 Accessing the Audit Vault Server Post-Install Configuration Page
- 4.4 Setting the Usernames and Passwords of Audit Vault Server Users
- 4.5 Setting the Audit Vault Server Time (Strongly Recommended)
- 4.6 Setting the Audit Vault Server DNS Servers (Recommended)
- 4.7 Networking Setup And Configuration
-
5
Behavior Changes, Deprecated, and Desupported
Platforms and Features
- 5.1 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.13
- 5.2 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.12
- 5.3 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.11
- 5.4 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.10
- 5.5 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.9
- 5.6 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.8
- 5.7 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.7
- 5.8 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.6
- 5.9 Behavior Changes, Deprecation, and Desupport Notices in Oracle Audit Vault and Database Firewall 20.1
-
6
Patching Oracle Audit Vault and Database
Firewall Release 20
- 6.1 About Patching Oracle Audit Vault and Database Firewall
- 6.2 Download the Files
- 6.3 Pre-update Tasks
- 6.4 Update the Audit Vault Server
- 6.5 Verify That Audit Vault Agents and Host Monitor Agents Were Automatically Updated
- 6.6 Update the Database Firewalls
-
6.7
Post-update Tasks
- 6.7.1 Confirm the Update Process
- 6.7.2 Post Upgrade Agent User Security Hardening
- 6.7.3 Enable Administrator Access to Existing Archive Locations
- 6.7.4 Enable Archiving Functionality for High Availability
- 6.7.5 Clear Unused Kernels from Oracle Audit Vault and Database Firewall
- 6.7.6 Check the Observer Status After Updating to Oracle AVDF 20.7 or Later for High Availability
- 6.7.7 Configure Audit Vault Server Backups
- 6.7.8 Schedule Maintenance Jobs
- 6.7.9 Enable FIPS Mode If It Was Disabled Before Patching to AVDF 20.10
- 6.7.10 Update Alert Notification Template for Alert Policies After Patching to AVDF 20.11
- 6.7.11 Retrieve Audit Policies After Patching to 20.12
- 6.8 Recover the Database If an Update Fails
-
6.9
Updating Oracle AVDF with Minimal Downtime by
Using Backup and Restore
- 6.9.1 About the Update Process
- 6.9.2 Prerequisites
-
6.9.3
Configure the Source and Destination Audit
Vault Servers
- 6.9.3.1 Patch Bug Numbers for the Source and Destination Audit Vault Servers
- 6.9.3.2 Create an NFS Location as an Archive Log Destination for the Source Audit Vault Server
- 6.9.3.3 Configure the Source Audit Vault Server for Replication
- 6.9.3.4 Configure the Destination Audit Vault Server for Replication
- 6.9.4 Create a Hot Backup of the Source Audit Vault Server
- 6.9.5 Restore the Hot Backup to the Destination Audit Vault Server
- 6.9.6 Set the Archive Log Destination on the Destination Audit Vault Server
- 6.9.7 Update the Destination Audit Vault Server to the Latest Release
- 6.9.8 (High Availability Only) Pair the Primary and Standby Audit Vault Servers
-
6.9.9
Replicate the Data That Was Collected During
the Update Process
- 6.9.9.1 Start the Replication on the Destination Audit Vault Server
- 6.9.9.2 Check the Replication Status on the Destination Audit Vault Server
- 6.9.9.3 Set Up the Purge Task on the Destination Audit Vault Server
- 6.9.9.4 Check the Replication Lag Time on the Destination Audit Vault Server
- 6.9.9.5 Stop All Monitoring Points and Audit Trails on the Source Audit Vault Server
- 6.9.9.6 Stop the Replication on the Destination Audit Vault Server
- 6.9.10 Update and Migrate All Monitoring and Collection to the Destination Audit Vault Server
- 6.9.11 Start All Audit Trails on the Destination Audit Vault Server
- 6.9.12 Uninstall the Replication Patches from the Source and Destination Audit Vault Servers
-
7
Upgrading Oracle Audit Vault and Database
Firewall from Release 12.2 to Release 20
- 7.1 About Upgrading Oracle Audit Vault and Database Firewall
-
7.2
Upgrading from Oracle AVDF 12.2 to Release
20.8
- 7.2.1 Download the Files
-
7.2.2
Pre-update Tasks
- 7.2.2.1 Migrate Host Monitor Agent on Windows
- 7.2.2.2 Back Up the Current Oracle Audit Vault and Database Firewall Installation
- 7.2.2.3 Set the Host Monitor Agent and Audit Vault Agent TLS Version
- 7.2.2.4 Ensure That the System Has Sufficient Space to Purge the Alert Queue
- 7.2.2.5 Release Existing Tablespaces That Are Retrieved Manually
- 7.2.2.6 Preserve File Customizations
- 7.2.2.7 Ensure That the Boot Device Is Less Than 2 TB
- 7.2.2.8 Ensure That the Boot Partition Has at Least 500 MB
- 7.2.2.9 Verify That the SYS User Is Unlocked and the Password Is Not Expired
- 7.2.3 Update the Audit Vault Server
- 7.2.4 Verify That Audit Vault Agents and Host Monitor Agents Were Automatically Updated
-
7.2.5
Update the Database Firewalls
- 7.2.5.1 Update a Standalone Database Firewall
- 7.2.5.2 Update a Pair of Database Firewalls That Are Configured for High Availability
-
7.2.6
Post-update Tasks
- 7.2.6.1 Confirm the Update Process
- 7.2.6.2 Post Upgrade TLS Security Hardening
- 7.2.6.3 Post Upgrade Agent User Security Hardening
- 7.2.6.4 Add Preexisting SQL Clusters to New Cluster Sets After Upgrading
- 7.2.6.5 Change the Database Firewall In-line Bridge to an Equivalent Proxy Configuration
- 7.2.6.6 Enable Administrator Access to Existing Archive Locations
- 7.2.6.7 Enable Archiving Functionality for High Availability
- 7.2.6.8 Clear Unused Kernels from Oracle Audit Vault and Database Firewall
- 7.2.6.9 Check the Observer Status After Updating to Oracle AVDF 20.7 or Later for High Availability
- 7.2.6.10 Configure Audit Vault Server Backups
- 7.2.6.11 Schedule Maintenance Jobs
- 7.2.6.12 Add a Privilege to the Native Network Encryption User for Decrypting the Native Network Encryption
- 7.2.6.13 Retrieving the Security Assessment and Resetting the Baseline to a DBSAT 3.1 Assessment
- 7.2.7 Recover the Database If an Update Fails
- 7.3 Patching Oracle AVDF 20.8 to Apply the Latest Release Update
- 8 Uninstalling Oracle Audit Vault and Database Firewall
-
A
Troubleshooting Oracle Audit Vault and Database Firewall
- A.1 Information to Provide Support When Filing a Service Request
- A.2 Error When Installing Audit Vault Server in Releases 20.1 to 20.3
- A.3 Conflicting Data on Storage Added to Oracle AVDF
- A.4 EFI Related Error When Installing Audit Vault Server on VMware
- A.5 Cannot Access the Audit Vault Server Console
- A.6 Collecting Logs to Debug Installation Failures
- A.7 Unable to Reach Gateway Error
- A.8 Issue with Configuring or Managing Oracle AVDF through Oracle Enterprise Manager Cloud Control
- A.9 Installation Stops Progressing After Entering the IP Address
- A.10 No Signal Error During Post-Install Tasks
-
A.11
Pre-upgrade RPM Warnings
- A.11.1 RPM Upgrade Failed
- A.11.2 Uninstalling the Pre-Upgrade RPM for AVDF 20.12 and Later Doesn't Remove Filesystem
- A.11.3 Pre-upgrade RPM Failure Due to Insufficient Memory
- A.11.4 Insufficient Space Error in /var/lib/oracle File System Reported by Pre-upgrade RPM
- A.11.5 Insufficient Space Error in / File System Reported by Pre-upgrade RPM
- A.11.6 Pre-upgrade RPM Could Not Stop Certain Processes During Oracle AVDF Upgrade
- A.11.7 Pre-upgrade RPM Fails with "Unable to Stop Observer"
- A.11.8 Pre-upgrade RPM Check: Alert Queue Space Warning
- A.11.9 Pre-upgrade RPM Check: Boot Device Is Greater Than 2 TB
- A.11.10 Pre-upgrade RPM Check: Boot Partition Space Warning
- A.11.11 Pre-upgrade RPM Check: Legacy Crypto Warning
- A.11.12 Pre-upgrade RPM Fails with "Not All Processes Were Stopped"
- A.11.13 Pre-upgrade RPM Check: Agent Failure Checks - Upgrade Prerequisites
- A.12 SSH Becomes Disabled After Updating Oracle AVDF with FIPS Enabled
- A.13 SSH Connection Times Out When Uninstalling the Pre-Upgrade RPM
- A.14 Installation Pauses After Entering the Root Password
- A.15 When Upgrading to Oracle AVDF 20.3 ELMIG_POPULATE_CLUSTERS_202 and ELMIG_CONVERT_HASH_202 Are Reported as INVALID in dba_objects Table
- A.16 Error Occurred Trying to Format SDAF1 When Installing Oracle AVDF
- A.17 Audit Vault Agent Failed on Startup: OAV-10: Failed to Release Connection to DB
- A.18 Upgrade to AVDF 20.4 Failed During upgrade_apex Step
- A.19 Missing "Save as" Option in Web Console After Upgrading Oracle Audit Vault Server
- A.20 Oracle AVDF 20.7 Installation Fails Due to Package Download Error
- A.21 Calculating Minimum Required In-Memory Size for AVDF to Prevent "Insufficient Memory" Errors
- A.22 Upgrading 20.12 to 20.13 Fails on VMware With Error at Privileged Migrations Step
- A.23 Package Version Mismatch After Patching Leading to Perl Package Update Failure
-
B
Installing Oracle AVDF on Oracle Database
Appliance (ODA)
- B.1 Completing the Installation Prerequisites
- B.2 Download the Oracle AVDF ISO Files
- B.3 Installing KVM on ODA VM Instance for Running Oracle AVDF
- B.4 Configuring the Network on ODA VM Instance
- B.5 Installing the Audit Vault Server on the ODA VM Instance
- B.6 Installing the Database Firewall on the ODA VM Instance