Path: dp-news.maxwell.syr.edu!spool.maxwell.syr.edu!news-spur1.maxwell.syr.edu!news.maxwell.syr.edu!postnews.google.com!g43g2000cwa.googlegroups.com!not-for-mail
From: "felipe.rivabem@gmail.com" <felipe.rivabem@gmail.com>
Newsgroups: comp.databases.oracle.server
Subject: Warn on login failure
Date: 2 Feb 2006 09:44:28 -0800
Organization: http://groups.google.com
Lines: 25
Message-ID: <1138902268.529983.284640@g43g2000cwa.googlegroups.com>
NNTP-Posting-Host: 200.193.170.100
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Trace: posting.google.com 1138902275 7484 127.0.0.1 (2 Feb 2006 17:44:35 GMT)
X-Complaints-To: groups-abuse@google.com
NNTP-Posting-Date: Thu, 2 Feb 2006 17:44:35 +0000 (UTC)
User-Agent: G2/0.2
X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1,gzip(gfe),gzip(gfe)
X-HTTP-Via: 1.1 BR88
Complaints-To: groups-abuse@google.com
Injection-Info: g43g2000cwa.googlegroups.com; posting-host=200.193.170.100;
   posting-account=xj7RnQ0AAADgfQFrUxK3x5JyuDZhBGTj
Xref: dp-news.maxwell.syr.edu comp.databases.oracle.server:260574

Hi

We already have a logon audit on our server, but we wish to have more
control for some special users, like sys, system and some application
schemas we use.

Is there a way to be warned when there=B4s a failed login attempt using
these users? Failed login do nothing on the database, except for
writing audit, so, no triggers..

A job or cron to query dba_audit_session each couple of minutes is too
heavy as the query execution consume about 45 seconds.

We need the information fastly, because we have some shared machines,
and hours laters reports leave us with there=B4s no way to know who was
there on that moment. And we already had some problems, like account
locking of these application schemas (some are always locked, but some,
third party, are needed to be opened).

Any ideas?

Thanks

Luiz Felipe Rivabem

