Solved

Oracle constantly making audit logs

Posted on 2013-01-16
8
792 Views
Last Modified: 2013-01-23
I'm on Oracle 11.2.02 and recently our AIX admins have been saying they've been getting constant audits of failed make directories under my oracle diag home. Has anyone ran into this problem? The directory it keeps on trying to make already exists so the mkdirs actually fail. Below is a snippet of what the AIX admin's audit looks like. Anyone input/advice is greatly appreciated!


Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/trace
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/alert
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/incident
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata_pv
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata_dgif
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/hm
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/ir
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/incpkg
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/sweep
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/lck
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/cdump
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/stage
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag
Wed Jan 16 14:26:19 2013 FILE_Mode       OK          userj  16842998 1        69927151
        mode: 775 filename /server1/oracle/diag
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
0
Comment
Question by:themeeper1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 23

Expert Comment

by:David
ID: 38784145
Have userj test in the script that if the directory exists, skip it.  However, the permissions suggest s/he is trying to recreate part of the ORACLE BASE tables -- if so, s/b as oracle.
0
 

Author Comment

by:themeeper1
ID: 38784280
That directory already exists so it technically skips it but for some reason Oracle isn't recognizing that that directory exists.
0
 
LVL 40

Assisted Solution

by:mrjoltcola
mrjoltcola earned 125 total points
ID: 38784413
This is something you have to get accustomed to if you are auditing system calls at the OS level. Failure return codes from sys-calls are common and normal in correctly designed software. Oracle's internal implementation may make system calls like mkdir() without regard for whether the directory preexists or not. This isn't a bug, IMO, and should just be ignored.
0
PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

 
LVL 23

Assisted Solution

by:David
David earned 125 total points
ID: 38784417
Guess, and only a guess, your auditing is configured to capture all results -- and not to skip for this common-sense condition.  We would have to learn much more about your audit setup, and before do you so, do you have access to Oracle Support instead?
0
 

Author Comment

by:themeeper1
ID: 38784507
Mrjoltcola - I agree this is a normal OS audit but these failed mkdirs occur 10 or 15 times every second. I've tailed the log and it's just flying by.

dvz - I asked oracle support, but they weren't able to provide any clear reason why or how to stop this.
0
 
LVL 37

Assisted Solution

by:Geert Gruwez
Geert Gruwez earned 250 total points
ID: 38786047
oracle support didn't have a solution ?
they are only human after all

did you start a full database trace to see where it's coming from ?
> you might not want to run that for long
0
 

Author Comment

by:themeeper1
ID: 38787767
Yeah I did a database trace and didn't find anything.

It's really odd because these failed mkdirs are being generated every second. It's almost as if Oracle doesn't realize this directory exists. Is there some parameter where I can check to see if oracle recognizes the directory as being valid or registered? Thanks for all the input I've received.
0
 
LVL 37

Accepted Solution

by:
Geert Gruwez earned 250 total points
ID: 38792041
i came across an 2 orphaned threads in an oracle 9 on windows 2K3 a few weeks ago.
was a pain in locating the problem too.

they only way i found was to use process explorer, find the orphaned threads by looking at the 100%cpu usage and kill the oracle threads from process explorer.

since then the database has run fine

maybe you have some orphaned threads in the database ?
http://troubleshootingappsdba.blogspot.be/2008/02/orphan-processes-in-oracle-databases.html
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article started out as an Experts-Exchange question, which then grew into a quick tip to go along with an IOUG presentation for the Collaborate confernce and then later grew again into a full blown article with expanded functionality and legacy…
How to Unravel a Tricky Query Introduction If you browse through the Oracle zones or any of the other database-related zones you'll come across some complicated solutions and sometimes you'll just have to wonder how anyone came up with them.  …
This video explains at a high level with the mandatory Oracle Memory processes are as well as touching on some of the more common optional ones.
This video shows how to copy an entire tablespace from one database to another database using Transportable Tablespace functionality.

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question