Chuyển đến nội dung chính

Oracle IDM Auditing

Source: https://abhirockzz.wordpress.com
Reporting 
is a vital functionality in any product which deals with sensitive information. Same applies to Identity & Access Management tools. Oracle IDM’s Auditing module acts as a foundation for its OOTB Reporting capabilities. Let’s take a quick look at Auditing engine and how it facilitates the Reporting functionality within OIM
The use case presented here is simple – change to a user record in OIM.
What are the sequence of events which get triggered from an Audit perspective?
This is best explained by a diagram. I came up with the figure below in an attempt to better articulate the process.

oim-auditing
Although the diagram is self explanatory, a theoretical translation of the same is not going to harm us! 
  • The updated/created user record gets pushed into the USR table (stores the user information) – Its a normal process by which the information gets recorded in the OIM Database
  • The information is further propagated by the OIM Auditing engine (as a part of core back end server logic) and it initiates a transaction
  • The Audit Engine inserts a new entry in the AUD_JMS table as a part of the audit transaction completion. The AUD_JMS table is nothing but a staging table
  • The Issue Audit Messages scheduled job picks up the Audit messages in the AUD_JMS table and submits the key to the oimAuditQueue JMS queue.
  • The MDB corresponding to the queue initiates the Audit data processing – the data is seeded into the UPA table. This data is in the form of XML. These are snapshots of the user profile at the instant when the user record was actually modified/created. The UPA table also stores the delta (changes to the profile)
  • Finally, the Post processors of the Audit engine pick up the XML snapshots from the central UPA table and store them in specific audit tables (in a de-normalized format) like UPA_USR, UPA_USR_FIELDS, UPA_RESOURCE, UPA_UD_FORMS etc
  • These tables serve as the primary source of information for the Reporting module. If you have ever worked on the OIM Reporting module, I am sure you can relate to the Data Sources which you configure on your BI Publisher instance – these are for executing direct queries on the above mentioned Audit tables for its data.

Nhận xét

Bài đăng phổ biến từ blog này

Registering a Plugin using OIM APIs

Version: Oracle Identity Manager 11g R2 package com.oracle.utility; import java.io.File; import java.io.FileInputStream; import java.io.FileNotFoundException; import java.io.IOException; import java.util.Hashtable; import java.util.logging.Level; import java.util.logging.Logger; import javax.security.auth.login.LoginException; import oracle.iam.platform.OIMClient; import oracle.iam.platform.pluginframework.PluginException; import oracle.iam.platformservice.api.PlatformService; import oracle.iam.platformservice.api.PlatformUtilsService; import oracle.iam.platformservice.exception.PlatformServiceAccessDeniedException; /**  * @author Pham Thanh Tung  * Email: phamthanhtungdcn@gmail.com  * 21-06-2017  */ public class RegisterPlugin {     public static final String OIM_HOSTNAME = "10.4.18.101";     public static final String OIM_PORT = "14000";     public static final String OIM_PROVIDER_URL = "t3://"+ OIM_HOSTNAME + "...

Rich Diagnostics

Source: https://abhirockzz.wordpress.com Oracle IDM R2 PS2 provides some really efficient troubleshooting, monitoring and diagnostic features. This post will provide a quick overview of the same and delve into using one such feature to resolve a practical issue. New Diagnostic Features: Overview 1.  Orchestration diagnostics  – The EM console can be used to drill down into the Orchestration related details of events within OIM      A  Dashboard  to view recent operations and events Info regarding  ALL the event handlers  attached to a particular operation – including   CUSTOM  developed. No more digging into XMLs form MDS ! Powerful  search  features for all  Operations  (search by Operation Type, Operation ID etc) 2.  Dynamic Monitoring Service (DMS)  is an Oracle FMW component which enables  performance tracking  of various OIM modules and ...

Uninstalling an OIM Connector

Version: Oracle Identity Manager 11.1.2.3.0 Step 1: Modify "ConnectorUninstall.properties" located in the "/home/oracle/Oracle/Middleware/Oracle_IDM1/server/bin" directory. Step 2: Here is a brief description of each parameter defined in the file: DatabaseURL: location of the Oracle Database DbUserName: Name of the OIM schema Location: Place where you want the log files of this process to be. ConnectorName: Name of the connector (Same as in the OIM console: Advanced-> Manage Connector -> search. Use the Connector Name field.) Step 3: Run the" uninstallConnector.sh" script located in "/home/oracle/Oracle/Middleware/Oracle_IDM1/server/bin" directory. [Enter the DB Password :] <OIM schema password> [Enter OIM Administrator Name :] xelsysadm [Enter the OIM Administrator Password :] [Enter OIM Server t3 URL [Ex. t3://localhost:7001/ ]:] t3://localhost:14000 Step 4: Execute the "DeleteJars.sh...