Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Example Analysis of mysql Audit

2025-03-29 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Database >

Share

Shulou(Shulou.com)05/31 Report--

This article shares with you the content of a sample analysis of mysql auditing. The editor thinks it is very practical, so share it with you as a reference and follow the editor to have a look.

Mysql audit plug-in

Download address of the binary package for the audit audit plug-in:

Go to the https://bintray.com/mcafee/mysql-audit-plugin/release website to download the corresponding binary package.

The name is audit-plugin-mysql-5.6-1.1.2-694-linux-x86_64.zip to view the MySQL plug-in directory:

Mysql > show global variables like 'plugin_dir'

+-- +

| | Variable_name | Value |

+-- +

| | plugin_dir | / usr/local/mysql/lib/plugin/ |

+-- +

1 row in set (0.00 sec) mysql > quit

Bye unzip and cp libaudit_plugin.so to the plugin directory corresponding to MySQL:

# cd / root

# unzip audit-plugin-mysql-5.6-1.1.2-694-linux-x86_64.zip

Archive: audit-plugin-mysql-5.6-1.1.2-694-linux-x86_64.zip

Creating: audit-plugin-mysql-5.6-1.1.2-694 /

Creating: audit-plugin-mysql-5.6-1.1.2-694/lib/

Inflating: audit-plugin-mysql-5.6-1.1.2-694/lib/libaudit_plugin.so

Inflating: audit-plugin-mysql-5.6-1.1.2-694/COPYING

Inflating: audit-plugin-mysql-5.6-1.1.2-694/THIRDPARTY.txt

Inflating: audit-plugin-mysql-5.6-1.1.2-694/README.txt

Creating: audit-plugin-mysql-5.6-1.1.2-694/utils/

Inflating: audit-plugin-mysql-5.6-1.1.2-694/utils/offset-extract.sh# cd / root/audit-plugin-mysql-5.6-1.1.2-694/lib# cp libaudit_plugin.so / usr/local/mysql/lib/plugin/

# cd / usr/local/mysql/lib/plugin/

# chmod + x libaudit_plugin.so edit / etc/my.cnf, add the following:

Plugin-load=AUDIT=libaudit_plugin.so# service mysqld restart

Shutting down MySQL. [OK]

Starting MySQL. [OK] or use the command to install plugin:

Mysql > INSTALL PLUGIN AUDIT SONAME 'libaudit_plugin.so'; to view the installed plugin:

Mysql > show plugins

+-+

| | Name | Status | Type | Library | License | |

+-+

| | binlog | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | mysql_native_password | ACTIVE | AUTHENTICATION | NULL | GPL | |

| | mysql_old_password | ACTIVE | AUTHENTICATION | NULL | GPL | |

| | sha256_password | ACTIVE | AUTHENTICATION | NULL | GPL | |

| | MyISAM | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | MRG_MYISAM | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | MEMORY | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | CSV | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | BLACKHOLE | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | InnoDB | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | INNODB_TRX | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_LOCKS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_LOCK_WAITS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_CMP | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_CMP_RESET | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_CMPMEM | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_CMPMEM_RESET | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_CMP_PER_INDEX | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_CMP_PER_INDEX_RESET | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_BUFFER_PAGE | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_BUFFER_PAGE_LRU | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_BUFFER_POOL_STATS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_METRICS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_FT_DEFAULT_STOPWORD | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_FT_DELETED | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_FT_BEING_DELETED | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_FT_CONFIG | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_FT_INDEX_CACHE | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_FT_INDEX_TABLE | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_TABLES | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_TABLESTATS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_INDEXES | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_COLUMNS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_FIELDS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_FOREIGN | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_FOREIGN_COLS | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_TABLESPACES | ACTIVE | INFORMATION SCHEMA | NULL | GPL | |

| | INNODB_SYS_DATAFILES | ACTIVE | INFORMATION SCHEMA | NULL |

Offset-extract.txt

| | GPL |

| | PERFORMANCE_SCHEMA | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | FEDERATED | DISABLED | STORAGE ENGINE | NULL | GPL | |

| | ARCHIVE | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | partition | ACTIVE | STORAGE ENGINE | NULL | GPL | |

| | AUDIT | ACTIVE | AUDIT | libaudit_plugin.so | GPL | |

+-+

43 rows in set (0.00 sec) you can see the word AUDIT libaudit_plugin.so on the last line, indicating that the installation was successful.

Mysql > SHOW GLOBAL VARIABLES LIKE 'audit%'

+- - - -- +

| | Variable_name | Value |

+- - - -- +

| | audit_before_after | after |

| | audit_checksum |

| | audit_client_capabilities | OFF |

| | audit_delay_cmds |

| | audit_delay_ms | 0 | |

| | audit_force_record_logins | OFF |

| | audit_header_msg | ON |

| | audit_json_file | OFF |

| | audit_json_file_bufsize | 1 | |

| | audit_json_file_flush | OFF |

| | audit_json_file_retry | 60 | |

| | audit_json_file_sync | 0 | |

| | audit_json_log_file | mysql-audit.json |

| | audit_json_socket | OFF |

| | audit_json_socket_name | / var/run/db-audit/mysql.audit__usr_local_mysql_data_3306 |

| | audit_json_socket_retry | 10 | |

| | audit_offsets |

| | audit_offsets_by_version | ON |

| | audit_password_masking_cmds | CREATE_USER,GRANT,SET_OPTION,SLAVE_START,CREATE_SERVER,ALTER_SERVER,CHANGE_MASTER,UPDATE |

| | audit_password_masking_regex | identified (?: /\ *. *?\ * / |\ s) *? by (?: /\ *. *?\ * / |\ s) *? (?: password)? (? /\ *. * / |\ s) *? ['| "] (?. *?) (?

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Database

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report