Init parameterSecurity & auditing
AUDIT_SYS_OPERATIONS
What it controls
Audits top-level statements run as SYS, SYSDBA and SYSOPER to OS files.
Know this before you change it
Keep it on; it's the only record of what SYS did.
Default: TRUE
Check and change it
1-- Current value on every instance2SELECT inst_id, name, value, isdefault, ismodified3FROM gv$parameter4WHERE name = 'audit_sys_operations';5 6-- Value stored in the spfile7SELECT sid, value FROM v$spparameter WHERE name = 'audit_sys_operations' AND isspecified = 'TRUE';8 9-- Static: saved in the spfile, takes effect after a restart10ALTER SYSTEM SET audit_sys_operations = TRUE SCOPE = SPFILE SID = '*';11 12-- Remove it from the spfile to go back to the default at the next restart13ALTER SYSTEM RESET audit_sys_operations SCOPE = SPFILE SID = '*';Open in the parameter referenceOracle's reference
More in Security & auditing
- AUDIT_TRAILWhere traditional auditing records go.
- AUDIT_FILE_DESTDirectory for OS audit files, including SYS audit records.
- REMOTE_LOGIN_PASSWORDFILEWhether a password file is used for remote SYSDBA connections.
- SEC_MAX_FAILED_LOGIN_ATTEMPTSFailed attempts on one connection before the server drops it.