Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Oracle constantly making audit logs

Posted on 2013-01-16
8
Medium Priority
?
829 Views
Last Modified: 2013-01-23
I'm on Oracle 11.2.02 and recently our AIX admins have been saying they've been getting constant audits of failed make directories under my oracle diag home. Has anyone ran into this problem? The directory it keeps on trying to make already exists so the mkdirs actually fail. Below is a snippet of what the AIX admin's audit looks like. Anyone input/advice is greatly appreciated!


Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/trace
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/alert
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/incident
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata_pv
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata_dgif
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/hm
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/ir
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/incpkg
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/sweep
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/lck
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/cdump
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/stage
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag
Wed Jan 16 14:26:19 2013 FILE_Mode       OK          userj  16842998 1        69927151
        mode: 775 filename /server1/oracle/diag
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
0
Comment
Question by:themeeper1
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 23

Expert Comment

by:David
ID: 38784145
Have userj test in the script that if the directory exists, skip it.  However, the permissions suggest s/he is trying to recreate part of the ORACLE BASE tables -- if so, s/b as oracle.
0
 

Author Comment

by:themeeper1
ID: 38784280
That directory already exists so it technically skips it but for some reason Oracle isn't recognizing that that directory exists.
0
 
LVL 40

Assisted Solution

by:mrjoltcola
mrjoltcola earned 500 total points
ID: 38784413
This is something you have to get accustomed to if you are auditing system calls at the OS level. Failure return codes from sys-calls are common and normal in correctly designed software. Oracle's internal implementation may make system calls like mkdir() without regard for whether the directory preexists or not. This isn't a bug, IMO, and should just be ignored.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 23

Assisted Solution

by:David
David earned 500 total points
ID: 38784417
Guess, and only a guess, your auditing is configured to capture all results -- and not to skip for this common-sense condition.  We would have to learn much more about your audit setup, and before do you so, do you have access to Oracle Support instead?
0
 

Author Comment

by:themeeper1
ID: 38784507
Mrjoltcola - I agree this is a normal OS audit but these failed mkdirs occur 10 or 15 times every second. I've tailed the log and it's just flying by.

dvz - I asked oracle support, but they weren't able to provide any clear reason why or how to stop this.
0
 
LVL 38

Assisted Solution

by:Geert Gruwez
Geert Gruwez earned 1000 total points
ID: 38786047
oracle support didn't have a solution ?
they are only human after all

did you start a full database trace to see where it's coming from ?
> you might not want to run that for long
0
 

Author Comment

by:themeeper1
ID: 38787767
Yeah I did a database trace and didn't find anything.

It's really odd because these failed mkdirs are being generated every second. It's almost as if Oracle doesn't realize this directory exists. Is there some parameter where I can check to see if oracle recognizes the directory as being valid or registered? Thanks for all the input I've received.
0
 
LVL 38

Accepted Solution

by:
Geert Gruwez earned 1000 total points
ID: 38792041
i came across an 2 orphaned threads in an oracle 9 on windows 2K3 a few weeks ago.
was a pain in locating the problem too.

they only way i found was to use process explorer, find the orphaned threads by looking at the 100%cpu usage and kill the oracle threads from process explorer.

since then the database has run fine

maybe you have some orphaned threads in the database ?
http://troubleshootingappsdba.blogspot.be/2008/02/orphan-processes-in-oracle-databases.html
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction A previously published article on Experts Exchange ("Joins in Oracle", http://www.experts-exchange.com/Database/Oracle/A_8249-Joins-in-Oracle.html) makes a statement about "Oracle proprietary" joins and mixes the join syntax with gen…
Shell script to create broker configuration file using current broker Configuration, solely for purpose of backup on Linux. Script may need to be modified depending on OS-installation. Please deploy and verify the script in a test environment.
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
This video shows how to Export data from an Oracle database using the Datapump Export Utility.  The corresponding Datapump Import utility is also discussed and demonstrated.
Suggested Courses

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question