Re: userhost of unified_audit_trail shown as cryptic string

From: Niall Litchfield <niall.litchfield_at_gmail.com>
Date: Mon, 30 Apr 2018 16:57:48 +0100
Message-ID: <CABe10sb88zHN6r-58KHs0AsnXj+dqE+1PgzKzB7p0mjs91JOww_at_mail.gmail.com>



Indeed.

On Mon, Apr 30, 2018 at 4:54 PM, Stefan Knecht <knecht.stefan_at_gmail.com> wrote:

> Ahh interesting!
>
> Thanks for the follow-up
>
> On Mon, Apr 30, 2018 at 10:23 PM, Yong Huang <yong321_at_yahoo.com> wrote:
>
>> Thanks Stefan. The "cryptic" string turned out to be the docker container
>> ID. It has nothing to do with Oracle's audit trail or Oracle version. It's
>> in the machine column of v$session as well, as you suspected. And I'm told
>> sending out the container ID as hostname is the default behavior of docker
>> if the container's hostname is not set.
>>
>> Since there's no way to "decrypt" the string, I just use one of the two
>> ways to identify the host: Oracle audit trail (comment_text of
>> dba_audit_trail or authentication_type of unified_audit_trail); OS level
>> network connection (netstat -anp | grep <spid of v$process>, or lsof -p
>> ...).
>>
>> Yong Huang
>>
>
>
>
> --
> //
> zztat - The Next-Gen Oracle Performance Monitoring and Reaction Framework!
> Visit us at zztat.net | _at_zztat_oracle | fb.me/zztat | zztat.net/blog/
>

-- 
Niall Litchfield
Oracle DBA
http://www.orawin.info

--
http://www.freelists.org/webpage/oracle-l
Received on Mon Apr 30 2018 - 17:57:48 CEST

Original text of this message