zoukankan      html  css  js  c++  java
  • Oracle安全之Oracle日志挖掘

    logminer基于包:

    [oracle@localhost ~]$ ls /u01/oracle/10g/rdbms/admin/dbmslm.sql -->dbms_logmnr工具

    /u01/oracle/10g/rdbms/admin/dbmslm.sql

    [oracle@localhost ~]$ ls /u01/oracle/10g/rdbms/admin/dbmslmd.sql-->dbms_logmnr_d工具

    /u01/oracle/10g/rdbms/admin/dbmslmd.sql

    挖掘联机日志:

    SQL> execute dbms_logmnr.add_logfile

    ('/u01/oracle/oradata/orcl/redo03.log',dbms_logmnr.new);

    SQL> execute dbms_logmnr.add_logfile

    ('/u01/oracle/oradata/orcl/redo02.log',dbms_logmnr.addfile);

    SQL> execute dbms_logmnr.start_logmnr

    (options=>dbms_logmnr.dict_from_online_catalog+dbms_logmnr.committed_data_only);

    SQL> select sql_redo,sql_undo from v$logmnr_contents where table_name='EMP';

    SQL> create table tlog as select * from v$logmnr_contents;

    Table created.

    SQL> exec dbms_logmnr.end_logmnr();

    PL/SQL procedure successfully completed.

    挖掘归档日志:

    SQL> delete from dept where deptno=70;

    1 row deleted.

    SQL> commit;

    Commit complete.

    SQL> delete from dept where deptno=60;

    1 row deleted.

    SQL> commit;

    Commit complete.

    SQL> alter system switch logfile;

    System altered.

    SQL> alter system switch logfile;

    System altered.

    SQL> alter system switch logfile;

    System altered.

    SQL> select name from v$archived_log;

    NAME

    ------------------------------------------------------------------------------------------------------------------

    /u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_2_bkp6s8vy_.arc

    /u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_3_bkp6sdbz_.arc

    /u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_4_bkp6sjbz_.arc

    SQL> show parameter utl_file

    NAME TYPE VALUE

    ------------------------------------ ----------- ------------------------------

    utl_file_dir string

    SQL> alter system set utl_file_dir='/home/oracle/' scope=spfile;

    System altered.

    SQL> shutdown immediate

    Database closed.

    Database dismounted.

    ORACLE instance shut down.

    SQL> startup

    ORACLE instance started.

    Total System Global Area 285212672 bytes

    Fixed Size 1218968 bytes

    Variable Size 88082024 bytes

    Database Buffers 188743680 bytes

    Redo Buffers 7168000 bytes

    Database mounted.

    Database opened.

    SQL> exec dbms_logmnr_d.build('log.ora','/home/oracle/',dbms_logmnr_d.store_in_flat_file);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.add_logfile('/u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_12_bkr48xy4_.arc',dbms_logmnr.new);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.add_logfile('/u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_11_bkr48wsk_.arc',dbms_logmnr.addfile);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.add_logfile('/u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_10_bkr48vcs_.arc',dbms_logmnr.addfile);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.start_logmnr(dictfilename=>'/home/oracle/log.ora');

    PL/SQL procedure successfully completed.

    SQL> select sql_undo,sql_redo from v$logmnr_contents where table_name='EMP';

    no rows selected

    SQL> exec dbms_logmnr.end_logmnr();

    PL/SQL procedure successfully completed.

  • 相关阅读:
    剑指offer4:重建二叉树(后序遍历)
    剑指offer3:从尾到头打印链表每个节点的值
    剑指offer2:C++实现的替换空格(字符中的空格替换为“%20”)
    tp5系统变量输出(可以用来传递搜索的参数)
    Ajax实现文件上传的临时垃圾文件回收策略
    php获取当天的开始时间和结束时间
    Think PHP递归获取所有的子分类的ID (删除当前及子分类)
    tp查找某字段,排除某字段,不用一次写那么多
    git-查看历史版本及回滚版本
    dedecms目录结构,非常全
  • 原文地址:https://www.cnblogs.com/wcwen1990/p/6661683.html
Copyright © 2011-2022 走看看