mysql 5.7 安裝SQL審計

1、爲了數據庫安全準備開啓SQL審計功能,選用MariaDB Audit Plugin的插件(Oracle MySQL 5.7.24)

mysql> show variables like 'version';
+---------------+------------+
| Variable_name | Value      |
+---------------+------------+
| version       | 5.7.24-log |
+---------------+------------+
1 row in set (0.00 sec)

mysql> show variables like 'plugin_dir';
+---------------+--------------------------+
| Variable_name | Value                    |
+---------------+--------------------------+
| plugin_dir    | /usr/lib64/mysql/plugin/ |
+---------------+--------------------------+
1 row in set (0.01 sec)

2、下載插件並解壓

wget https://downloads.mariadb.com/MariaDB/mariadb-5.5.66/bintar-linux-x86_64/mariadb-5.5.66-linux-x86_64.tar.gz

tar -zxvf mariadb-5.5.66-linux-x86_64.tar.gz 

cp mariadb-5.5.66-linux-x86_64/lib/plugin/server_audit.so /usr/lib64/mysql/plugin/

chmod 755 /usr/lib64/mysql/plugin/server_audit.so

3、安裝插件並啓用

mysql> install plugin server_audit SONAME 'server_audit.so';
Query OK, 0 rows affected (0.00 sec)

mysql> show variables like '%audit%';
+-------------------------------+-----------------------+
| Variable_name                 | Value                 |
+-------------------------------+-----------------------+
| server_audit_events           |                       |
| server_audit_excl_users       |                       |
| server_audit_file_path        | server_audit.log      |
| server_audit_file_rotate_now  | OFF                   |
| server_audit_file_rotate_size | 1000000               |
| server_audit_file_rotations   | 9                     |
| server_audit_incl_users       |                       |
| server_audit_loc_info         |                       |
| server_audit_logging          | OFF                   |
| server_audit_mode             | 1                     |
| server_audit_output_type      | file                  |
| server_audit_query_log_limit  | 1024                  |
| server_audit_syslog_facility  | LOG_USER              |
| server_audit_syslog_ident     | mysql-server_auditing |
| server_audit_syslog_info      |                       |
| server_audit_syslog_priority  | LOG_INFO              |
+-------------------------------+-----------------------+
16 rows in set (0.00 sec)

mysql> set global server_audit_logging=1;
Query OK, 0 rows affected (0.00 sec)

4、配置文件添加啓動

vi /etc/my.cnf

[mysqld]
server_audit_logging=on

5、查看日誌

mysql> show variables like 'datadir';
+---------------+------------+
| Variable_name | Value      |
+---------------+------------+
| datadir       | /u01/data/ |
+---------------+------------+
1 row in set (0.00 sec)

tail -f /u01/data/server_audit.log 
20191203 17:15:03,mysql_node01,test_user,192.168.1.2,14016,573201,QUERY,test,'SHOW GLOBAL STATUS',0

6、配置說明
server_audit_logging:啓動或關閉審計
server_audit_events:指定記錄事件的類型,可以用逗號分隔的多個值(connect,query,table) ,默認爲空代表審計所有事件。
server_audit_incl_users:指定哪些用戶的活動將記錄,默認審計所有用戶,該變量比server_audit_excl_users優先級高
server_audit_excl_users:指定哪些用戶行爲不記錄
server_audit_output_type:指定日誌輸出類型,可爲SYSLOG或FILE,缺省輸出至審計文件

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章