Solved

Oracle constantly making audit logs

Posted on 2013-01-16
8
745 Views
Last Modified: 2013-01-23
I'm on Oracle 11.2.02 and recently our AIX admins have been saying they've been getting constant audits of failed make directories under my oracle diag home. Has anyone ran into this problem? The directory it keeps on trying to make already exists so the mkdirs actually fail. Below is a snippet of what the AIX admin's audit looks like. Anyone input/advice is greatly appreciated!


Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/trace
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/alert
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/incident
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata_pv
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata_dgif
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/hm
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/ir
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/incpkg
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/sweep
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/lck
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/cdump
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/stage
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms/dev/dev1/metadata
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag
Wed Jan 16 14:26:19 2013 FILE_Mode       OK          userj  16842998 1        69927151
        mode: 775 filename /server1/oracle/diag
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
        mode: 755 dir: /server1/oracle/diag/rdbms
Wed Jan 16 14:26:19 2013 FS_Mkdir        FAIL        userj  16842998 1        69927151
0
Comment
Question by:themeeper1
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 23

Expert Comment

by:David
ID: 38784145
Have userj test in the script that if the directory exists, skip it.  However, the permissions suggest s/he is trying to recreate part of the ORACLE BASE tables -- if so, s/b as oracle.
0
 

Author Comment

by:themeeper1
ID: 38784280
That directory already exists so it technically skips it but for some reason Oracle isn't recognizing that that directory exists.
0
 
LVL 40

Assisted Solution

by:mrjoltcola
mrjoltcola earned 125 total points
ID: 38784413
This is something you have to get accustomed to if you are auditing system calls at the OS level. Failure return codes from sys-calls are common and normal in correctly designed software. Oracle's internal implementation may make system calls like mkdir() without regard for whether the directory preexists or not. This isn't a bug, IMO, and should just be ignored.
0
 
LVL 23

Assisted Solution

by:David
David earned 125 total points
ID: 38784417
Guess, and only a guess, your auditing is configured to capture all results -- and not to skip for this common-sense condition.  We would have to learn much more about your audit setup, and before do you so, do you have access to Oracle Support instead?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:themeeper1
ID: 38784507
Mrjoltcola - I agree this is a normal OS audit but these failed mkdirs occur 10 or 15 times every second. I've tailed the log and it's just flying by.

dvz - I asked oracle support, but they weren't able to provide any clear reason why or how to stop this.
0
 
LVL 36

Assisted Solution

by:Geert Gruwez
Geert Gruwez earned 250 total points
ID: 38786047
oracle support didn't have a solution ?
they are only human after all

did you start a full database trace to see where it's coming from ?
> you might not want to run that for long
0
 

Author Comment

by:themeeper1
ID: 38787767
Yeah I did a database trace and didn't find anything.

It's really odd because these failed mkdirs are being generated every second. It's almost as if Oracle doesn't realize this directory exists. Is there some parameter where I can check to see if oracle recognizes the directory as being valid or registered? Thanks for all the input I've received.
0
 
LVL 36

Accepted Solution

by:
Geert Gruwez earned 250 total points
ID: 38792041
i came across an 2 orphaned threads in an oracle 9 on windows 2K3 a few weeks ago.
was a pain in locating the problem too.

they only way i found was to use process explorer, find the orphaned threads by looking at the 100%cpu usage and kill the oracle threads from process explorer.

since then the database has run fine

maybe you have some orphaned threads in the database ?
http://troubleshootingappsdba.blogspot.be/2008/02/orphan-processes-in-oracle-databases.html
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

Article by: Swadhin
From the Oracle SQL Reference (http://download.oracle.com/docs/cd/B19306_01/server.102/b14200/queries006.htm) we are told that a join is a query that combines rows from two or more tables, views, or materialized views. This article provides a glimps…
Introduction A previously published article on Experts Exchange ("Joins in Oracle", http://www.experts-exchange.com/Database/Oracle/A_8249-Joins-in-Oracle.html) makes a statement about "Oracle proprietary" joins and mixes the join syntax with gen…
This video shows how to copy a database user from one database to another user DBMS_METADATA.  It also shows how to copy a user's permissions and discusses password hash differences between Oracle 10g and 11g.
This videos aims to give the viewer a basic demonstration of how a user can query current session information by using the SYS_CONTEXT function

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now