OEM 13C关于"User SYS logged on from WORKGROUP\WIN-主机名"报警

 

OEM 13C关于"User SYS logged on from WORKGROUP\WIN-主机名"报警

 

前言

有时候OEM的邮件警报会出现如下的报警:

Host=xxxdb1 
Target type=Database Instance 
Target name=xxxxx_xxxxx1 
Categories=Security 
Message=User SYS logged on from WORKGROUP\WIN-主机名. 
Severity=Warning 
Event reported time=Dec 2, 2020 9:22:55 AM CST 
Operating System=Linux
Platform=x86_64 
Event Type=Metric Alert 
Event name=UserAudit:username 
Metric Group=User Audit
Metric=Audited User
Metric value=SYS
Key Value=SYS_WORKGROUP\WIN-主机名
Key Column 1=Audited User - Host
Rule Name=Incident management rule set for all targets,Clear metric alert events older than 7 days 
Rule Owner=System Generated

出现次数多了,就想着有没有办法禁用掉这类报警,没啥必要的提示。

 

禁用步骤

打开web端管理界面登陆后,按照如下截图来即可。

 

 

 

 

 可以通过查询agent调度信息查看调度是否包含UserAudit。

禁用前:
[
oracle@xxxxx2 ~]$ /oracle/app/oem13c/agent/agent_inst/bin/emctl status agent scheduler | grep UserAudit 2020-12-09 14:49:22.352 : oracle_database:xxxxx_xxxxx2:UserAudit 2020-12-09 14:51:59.384 : oracle_database:xxxxx2:UserAudit
禁用后:
[oracle@xxxxx2 ~]$ /oracle/app/oem13c/agent/agent_inst/bin/emctl status agent scheduler | grep UserAudit

 

 

参考文档

EM 12c, EM 13c How to Receive or Disable Notifications from the User Auditaudited user metric in Cloud Control 12c and 13c Cloud Control (Doc ID 1925442.1)

 

posted @ 2020-12-09 14:57  PiscesCanon  阅读(149)  评论(0编辑  收藏  举报