Re: userhost of unified_audit_trail shown as cryptic string

From: Stefan Knecht <knecht.stefan_at_gmail.com>
Date: Mon, 30 Apr 2018 22:54:00 +0700
Message-ID: <CAP50yQ-7isChtWjuKB6Abipox4psnLM6Zug4OvqQmxe=ci1bqQ_at_mail.gmail.com>



Ahh interesting!

Thanks for the follow-up

On Mon, Apr 30, 2018 at 10:23 PM, Yong Huang <yong321_at_yahoo.com> wrote:

> Thanks Stefan. The "cryptic" string turned out to be the docker container
> ID. It has nothing to do with Oracle's audit trail or Oracle version. It's
> in the machine column of v$session as well, as you suspected. And I'm told
> sending out the container ID as hostname is the default behavior of docker
> if the container's hostname is not set.
>
> Since there's no way to "decrypt" the string, I just use one of the two
> ways to identify the host: Oracle audit trail (comment_text of
> dba_audit_trail or authentication_type of unified_audit_trail); OS level
> network connection (netstat -anp | grep <spid of v$process>, or lsof -p
> ...).
>
> Yong Huang
>

-- 
//
zztat - The Next-Gen Oracle Performance Monitoring and Reaction Framework!
Visit us at zztat.net | _at_zztat_oracle | fb.me/zztat | zztat.net/blog/

--
http://www.freelists.org/webpage/oracle-l
Received on Mon Apr 30 2018 - 17:54:00 CEST

Original text of this message