Oracle 10 Audit via syslog
I've configured an Oracle 10 instance to send Audit log to enVision via syslog. In the Event Viewer I can see the incoming Oracle Audit messages, but when I try to make a Query I can't find the right table to use.
Anytime you're looking for the table(s) where your messages are winding up, the 1st place to look is under
Overview->System Configuration->Messages->Manage Messages To Parse
Find your device, Oracle in this case, look in the right-hand panel, and voila! - Database Audit is the only table all 558 messages are going.
As long as the messages are being recognized as the correct device type, your actual collection method is unrelated to the message destination.
Hope this answers your question.
Please check the log messages fall under defined categrory.
If the logs are classified under undefined events... then those messages cant be pulled out in a report form.
Note:- though the device got discovered under Oracle Device type, if the messages are grouped under the undefined messages, then you cannot pull those logs in the reports/ query.