zoukankan      html  css  js  c++  java
  • Oracle安全之Oracle日志挖掘

    logminer基于包:

    [oracle@localhost ~]$ ls /u01/oracle/10g/rdbms/admin/dbmslm.sql -->dbms_logmnr工具

    /u01/oracle/10g/rdbms/admin/dbmslm.sql

    [oracle@localhost ~]$ ls /u01/oracle/10g/rdbms/admin/dbmslmd.sql-->dbms_logmnr_d工具

    /u01/oracle/10g/rdbms/admin/dbmslmd.sql

    挖掘联机日志:

    SQL> execute dbms_logmnr.add_logfile

    ('/u01/oracle/oradata/orcl/redo03.log',dbms_logmnr.new);

    SQL> execute dbms_logmnr.add_logfile

    ('/u01/oracle/oradata/orcl/redo02.log',dbms_logmnr.addfile);

    SQL> execute dbms_logmnr.start_logmnr

    (options=>dbms_logmnr.dict_from_online_catalog+dbms_logmnr.committed_data_only);

    SQL> select sql_redo,sql_undo from v$logmnr_contents where table_name='EMP';

    SQL> create table tlog as select * from v$logmnr_contents;

    Table created.

    SQL> exec dbms_logmnr.end_logmnr();

    PL/SQL procedure successfully completed.

    挖掘归档日志:

    SQL> delete from dept where deptno=70;

    1 row deleted.

    SQL> commit;

    Commit complete.

    SQL> delete from dept where deptno=60;

    1 row deleted.

    SQL> commit;

    Commit complete.

    SQL> alter system switch logfile;

    System altered.

    SQL> alter system switch logfile;

    System altered.

    SQL> alter system switch logfile;

    System altered.

    SQL> select name from v$archived_log;

    NAME

    ------------------------------------------------------------------------------------------------------------------

    /u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_2_bkp6s8vy_.arc

    /u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_3_bkp6sdbz_.arc

    /u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_4_bkp6sjbz_.arc

    SQL> show parameter utl_file

    NAME TYPE VALUE

    ------------------------------------ ----------- ------------------------------

    utl_file_dir string

    SQL> alter system set utl_file_dir='/home/oracle/' scope=spfile;

    System altered.

    SQL> shutdown immediate

    Database closed.

    Database dismounted.

    ORACLE instance shut down.

    SQL> startup

    ORACLE instance started.

    Total System Global Area 285212672 bytes

    Fixed Size 1218968 bytes

    Variable Size 88082024 bytes

    Database Buffers 188743680 bytes

    Redo Buffers 7168000 bytes

    Database mounted.

    Database opened.

    SQL> exec dbms_logmnr_d.build('log.ora','/home/oracle/',dbms_logmnr_d.store_in_flat_file);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.add_logfile('/u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_12_bkr48xy4_.arc',dbms_logmnr.new);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.add_logfile('/u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_11_bkr48wsk_.arc',dbms_logmnr.addfile);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.add_logfile('/u01/oracle/flash_recovery_area/ORCL/archivelog/2015_04_01/o1_mf_1_10_bkr48vcs_.arc',dbms_logmnr.addfile);

    PL/SQL procedure successfully completed.

    SQL> exec dbms_logmnr.start_logmnr(dictfilename=>'/home/oracle/log.ora');

    PL/SQL procedure successfully completed.

    SQL> select sql_undo,sql_redo from v$logmnr_contents where table_name='EMP';

    no rows selected

    SQL> exec dbms_logmnr.end_logmnr();

    PL/SQL procedure successfully completed.

  • 相关阅读:
    在Apache下开启SSI配置
    ERROR 1290
    windows系统下Python环境的搭建
    php BC高精确度函数库
    mysql客户端(Navicat)远程登录操作遇到问题1142
    C与C++不同
    网易云课堂_C语言程序设计进阶_第七周:文件:文件访问、格式化输入输出、二进制输入输出
    面向对象程序设计-C++_课时30运算符重载——基本规则_课时31运算符重载——原型_课时32运算符重载——赋值_课时33运算符重载——类型转换
    面向对象程序设计-C++_课时28静态对象_课时29静态成员
    面向对象程序设计-C++_课时26拷贝构造Ⅰ_课时27拷贝构造Ⅱ
  • 原文地址:https://www.cnblogs.com/wcwen1990/p/6661683.html
Copyright © 2011-2022 走看看