Try our new research platform with insights from 80,000+ expert users
Director (Core Technology Services) and Partner at Nexim Solutions
Real User
Easy to deploy and use with flexible reporting and automation capabilities
Pros and Cons
  • "It has provided us with a unique opportunity to automate risk discovery."
  • "We would like to see the ability to administer and manage the solution through Enterprise Manager 13c, and development of the dashboards that are generally missing."

What is our primary use case?

We use this solution for regulatory compliance and reporting for the enterprise. This augments regular compliance and risk management solutions.

The organizations and clientele we work with include public sector and private sector businesses in the Financial Services industry, where they host data from global partners. The EU citizens and businesses now demand that GDPR be in place in order to host their data.

How has it helped my organization?

It has provided us with a unique opportunity to automate risk discovery.

The system provides both an audit system and a security solution through the database firewall that protects the data and databases being accessed.

The system uses BU internal risk management and audit teams for ease of IT and systems audits.

What is most valuable?

The most valuable features of this solution are:

  • Autonomous data collection.
  • Ease of deployment to work and integrate with heterogeneous platforms.
  • Reporting infrastructure is awesome and very flexible.
  • The interfaces are intuitive and easy to use and navigate through.
  • The solution has a well designed RBAC for the support of the business and it is secure.

What needs improvement?

We would like to see the ability to administer and manage the solution through Enterprise Manager 13c, and development of the dashboards that are generally missing.

The system needs to be easy to manage, especially in terms of space management.

There is little to no technical references and use cases pointing to the resolution of technical challenges during implementation. Better documentation would be helpful.

Buyer's Guide
Oracle Audit Vault
June 2025
Learn what your peers think about Oracle Audit Vault. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

For how long have I used the solution?

Five years.

What do I think about the stability of the solution?

The product is stable but extremely sensitive.

What do I think about the scalability of the solution?

It is rather difficult to scale, but it works perfectly.

How are customer service and support?

The technical support at Oracle is weak, but the documentation provided is detailed and good.

Unfortunately, there is little information available on Oracle MOS.

Which solution did I use previously and why did I switch?

We have always used the product alongside Imperva.

How was the initial setup?

This initial setup of this solution is straightforward.

What about the implementation team?

Our solution was delivered through an Oracle partner, Nexim Solutions.

What was our ROI?

Our ROI was almost immediate.

What's my experience with pricing, setup cost, and licensing?

It is affordable but technical skills are required to architect and set up the system.

Which other solutions did I evaluate?

We evaluated Imperva and Tivoli before choosing this solution.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are an Oracle Gold Partner
PeerSpot user
Senior Database Administrator at ITGStore
Real User
Enables our clients to see all of their past actions or the wrong activity done on the network
Pros and Cons
  • "Our clients can see all of their past actions or the wrong activity done on the network. We can load the diagnostics for the business."
  • "Some of our customers were asking about latency when the application wants to get to the database."

What is our primary use case?

We use Oracle Audit Vault to have a view of what is present on our network behind the firewall system. We use it to block threats and audit data for clients.

How has it helped my organization?

After we activate Oracle Audit Vault, our clients can see all of their past actions or the wrong activity done on the network. We can load most of the diagnostics for the business.

What is most valuable?

We have a situation for a bank as a client. We were able to deploy Oracle Audit Vault for them. The end-user is a key part of the system in the information department. 

For maintenance, only one person is required and he's an admin. Oracle Audit Vault was used extensively and our clients are quite comfortable with it.

We believe the product will be used for a long time.

What needs improvement?

One feature that was missing when we tried to update was the network activity analyzer. We found a request going through the database file before reaching the database. 

We don't have a database file in the middle. If it's possible to have that database file to analyze what's going on inside the network, it would be better.

Some of our customers were asking about the latency. When the application wants to get to the database, the database file is going to give some latency in operations.

The additional features we need are to be able to have the database firewall to scan the network to get the information from the database. 

I also want the database firewall to be able to block services with more granularity.

For how long have I used the solution?

We have been using the solution around one year.

How are customer service and technical support?

We have used Oracle technical support maybe twice. The support is nice. It was fast to install. The customer support is good.

Which solution did I use previously and why did I switch?

We didn't have a previous solution. We had a company come in with IBM to produce a proprietary solution. We also did a demo. 

How was the initial setup?

The initial set up was straightforward. It wasn't challenging. The implementation strategy for new customers doesn't take long. 

Our strategy is to increase the value of the software.

What about the implementation team?

We used a reseller.

What's my experience with pricing, setup cost, and licensing?

For the bank, the license was $48,000 last time. That was the licensing for the bank on just one license.

Which other solutions did I evaluate?

We had to do a demo to show management how the solution functions. That was useful for them to decide to go with Oracle Audit Vault over IBM.

What other advice do I have?

Anyone can go to with Oracle Audit Vault, but be sure you know what is going on to be comfortable with it.

On a scale from one to ten, I would rate this product at 8.5. Some of the database functionality is not too good.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Oracle Audit Vault
June 2025
Learn what your peers think about Oracle Audit Vault. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
ArchSolute344 - PeerSpot reviewer
Solution Architect at a tech services company with 51-200 employees
Real User
Separation of duty helps us to properly delineate between security and administration
Pros and Cons
  • "The solution is very stable and reliable."
  • "One feature that is missing is the ability to have a secret server that is always encrypted."

What is our primary use case?

We use this solution to provide for separation of duties based on database encryption.

What is most valuable?

We use the separation of duty feature because part of the database is encrypted, and the database administrators, such as myself, should have no access to this area. It belongs to the security team.

What needs improvement?

Right now, the ownership of the database is automatically given to the database administrator. I would like to have a software solution, separate from the Oracle product itself, to assign ownership of the database to a specific team, being our security team, rather than the default owner.

One feature that is missing is the ability to have a secret server that is always encrypted. I would like to see this in the next release of this solution.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

The solution is very stable and reliable.

What do I think about the scalability of the solution?

I would say that the scalability of this solution is medium.

The users include the database team, which has fifteen people, and in some areas of the business, there are in excess of fifty.

We are not currently planning to expand the use of this product.

How are customer service and technical support?

Technical support for this solution is very good. It is strong.

How was the initial setup?

I would say that the initial setup was of medium difficulty.

What about the implementation team?

We used an Oracle consultant to assist us with the implementation.

What other advice do I have?

I use this solution once or twice per month.

I would rate this solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Lead Network and Security at cb.gov.qa
Real User
Integration with our SIM facilitates auditing by providing us with a complete picture
Pros and Cons
  • "This solution acts as a complete data warehouse for our audit data."
  • "Customized reporting is something that we are struggling with, and it is quite tough for us."

What is our primary use case?

We have a few applications that use the Oracle Audit Vault as a broker service to log into the application. It uses the credentials provided by this solution. We are not using the firewall component.

How has it helped my organization?

This solution acts as a complete data warehouse for our audit data. Anytime we need to search for details about what happened, from a proactive monitoring perspective, or react to see what access permissions were granted or denied, we can look at this.

We have an alert mechanism implemented, and we also use some of the built-in reports. The reports are typically used by management, and we have a risk management dashboard. Management looks at the reports, and the indicators in them, to determine what level the security has been at over the past month. They can tell whether it has improved or gone down.

What is most valuable?

The most valuable feature is that Oracle Access Vault is integrated with our SIM (Security Information Management tool), which gives us a complete picture of what access is being provisioned in our organization. We do not use the interface provided by Oracle Audit Vault, except to export the data into our SIM.

What needs improvement?

The reporting is an area of the solution that needs to be improved.

Customized reporting is something that we are struggling with, and it is quite tough for us. Every time we need to prepare a custom report, we have to involve the vendor. This is unlike other solutions where the reports are easy to customize.

Another problem with reporting emerges on the topic of compliance and certain international standards. The standard set of reports do not provide sufficient details for the PCS and ISO standards.

It is important to have better integration with most of the tools to manage unstructured data or SIM solutions. If we change vendors for our SIM then we want to have the best possible support.

For how long have I used the solution?

More than four years.

What do I think about the stability of the solution?

This product is quite stable and robust. We have not faced any issues with respect to stability in the past few years.

What do I think about the scalability of the solution?

We do not have heavy requirements in terms of scalability on our end, so I am unsure.

We currently have between ten and twelve users. These people are middle management, our database administrator, and I am the Data Center Lead.

This solution is extensively used on a daily basis, as it is one of the pillars of our overall monitoring solution. We have no plans to increase usage at this time.

How are customer service and technical support?

Since our first contact with Mannai, they have been able to resolve most of our issues. Only in cases of problems that they cannot fix will they raise an SR with Oracle. Generally, they are quite capable.

Which solution did I use previously and why did I switch?

We did not use a specific solution prior to this one.

We do not use the database firewall component that is included with this solution. For our database activity monitoring, we rely on IBM Guardium.

How was the initial setup?

The installation itself is quite straightforward, but the configuration does not happen at the same time. We have fine-tuned our configuration over the past year or two, which has reduced the high number of false positives. We now only receive clear, actionable alerts. Most of these kinds of tools require a lot of fine-tuning to be done, based on your environment. It all depends on how fast you can do it, based on your database requirements.

It took approximately three months to deploy this solution and bring it into production.

What about the implementation team?

We used a reseller for assistance with the implementation of this solution. They are the Mannai Corporation, here in Doha, and they are quite good.

The majority of the deployment was handled by them, and we only had two people involved. These people were our DBA and backup DBA, and they are now users of the solution.

For the maintenance of this solution, if we have an issue then we simply call Mannai and they will come and fix it.

What was our ROI?

When it comes to security solutions it is very difficult to calculate ROI. There is no clear cut ROI for which you can put a number in terms of operational effectiveness or security-related components.

What's my experience with pricing, setup cost, and licensing?

This solution is definitely not expensive, and it is a small fraction of the overall database licensing costs. It is a simple add-on license, but it is not perpetual so we have to pay licensing fees every year.

Which other solutions did I evaluate?

We evaluated a lot of solutions before choosing this one, and some of them were used for a very long time. One of these was Imperva. The determining factor was the cost. Since we are already an Oracle customer, we received a large discount on the product.

Other than pricing, most of the solutions in the same space provide a similar type of output. The benefit of going with Oracle is, if you are using an Oracle database then the integration is quite strong internally.

What other advice do I have?

If you are with Oracle completely and you do not have a mix of databases then this is a great solution. However, if you have a solution that includes a mix of databases then it has a lot of limitations.

The advantage of going with Oracle Audit Vault comes from its integration with data encryption, masking, and all of the Oracle security technologies.

Overall, this solution delivers what it is intended to do and we are quite happy with the product. There are, however, improvements required in terms of reporting.

I would rate this solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Director (Core Technology Services) and Partner at Nexim Solutions
Real User
Offers inbuilt reports for GDPR and PCI compliance
Pros and Cons
  • "Our client was scheduled to take a year and a half to set up compliance, but by deploying this product they were able to do the compliance reports within three months."
  • "This solution doesn't audit the network."

What is our primary use case?

We use this solution primarily for GDPR and PCI compliance for the bank.

How has it helped my organization?

We were implementing this solution for our client, who was required to do PCI compliance. Their project was initially scheduled to run over a year and a half, but by just deploying this product they were able to do the compliance reports within three months, so the time to roll out was quite significant. The time was very short, which meant the turnaround time for compliance was much shorter and the value was realized, so that is one positive aspect that we experienced with our clients.

What is most valuable?

The most valuable feature is the ability to create inbuilt reports for compliance, which have dealt with the rules made it easier. This means that we don't have to develop them from scratch, which makes life so much easier.

What needs improvement?

One of the biggest challenges that we are facing is the inability to use more than one account for the platform, so the whole organization cannot make their own compliance audits at their own pace. I think that's one feature that really is giving us a bit of a problem. That is one of our biggest challenges.

The fact that it doesn't audit the network is also quite a downfall for the product. Maybe it should be improved to allow one to log on to network devices and do audits to check compliance at that level.

Finally, the ability to integrate with well-known applications like SAP, Microsoft, and common ERP would be helpful. If it included templates that are used for audits that can be used in those platforms and checking compliance, that would be really helpful, because half the time there isn't enough documentation to help someone check the compliances of specific applications. The second bit is the ability to audit middleware, like application servers and spatial and detection platforms. That is quite lacking in this product.

For how long have I used the solution?

We've been using this solution since 2011.

What do I think about the stability of the solution?

It's not a stable product, especially around log management and log generation. There are lots of logs and the administration or management is not as easy as one would expect. So you need a lot of DBA and unique skills in order to handle the virtual appliances. For us it was in our domain, but I don't think for any other organization it would be easy to readminister, especially when cable spaces are full and there are other challenges.

What do I think about the scalability of the solution?

It's very scalable. It can do real application, remote sites, and DR, so it's quite scalable. I think it's very easy to scale from that test; I think they've done well.

We've got at least 60 users, including IT demonstrators, auditors, and the risk department, so it's widely used.

It's currently used extensively at the bank because they have to measure their compliance in real time and they cannot do that without this solution. There were plans to integrate the solution with the ERT to start looking at certain components within ERT, as well as opportunities for them to expand it to be used on their distributions. I'm not too sure how far they have gone because we just deployed and left. We've not been back to these clients for this product so far.

How are customer service and technical support?

Oracle does not have very good documentation on this. I think Oracle abandoned the product, especially on the support side. It's not really one of the most friendly platforms where you can actually find help, but we've hung in there. We hope there will be a lot more opportunities for them to improve the support, half the people you talk to don't really know how to support the product. It's just frustrating, honestly.

The documentation is there, if very basic, but it doesn't help you address some of the more technical challenges.

Which solution did I use previously and why did I switch?

I had not used any other solution before Oracle. We deployed this particular solution because we are required to do PCI compliance. I don't think they could have used any other solution for this, without resorting to using lots of Excel sheets, reports, etc.

How was the initial setup?

It was very straightforward to set up, not too complex.

What about the implementation team?

Deployment took a month, and then the next month we set up the reports. However, the technical deployment took us only two weeks to do, including both the products and the development of the appliances. Our strategy was to deploy as is, using the standard report and customize the report as we go, instead of trying to come up with custom reports before deployment. That made it much easier, while still being adequate to satisfy the compliance department.

We are an integrator and our name is Making Solutions. So we are the ones who did the job. I only have three guys running the platform, so its quite easy to manage. From the client's staff, there are only two guys managing the platform.

What was our ROI?

They have had a good ROI because they were literally being audited and given lots of fines. All those things have disappeared within eight months. They were able to comply, submit reports on time, and actively correct whatever mistakes were picked up by the product. We use Oracle Enterprise Manager, which looks at other components to really add all the valuable information.

What's my experience with pricing, setup cost, and licensing?

For the bank, the licensing cost is about $360,000, annually.

For the value and cost of being compliant, the price is worth paying, because then you don't get auditors coming in left, right and center. Our clients spend a lot of money, but they also get their compliance guaranteed, so I think it's overall saving them money.

There are no additional fees to pay.

Which other solutions did I evaluate?

Our client did check another provider. I forgot the name of that product, but it was a big competitor of Oracle's solution.

What other advice do I have?

Those who want to implement it better have a proper detection in place, especially regarding documents. That's one thing that really drove us nuts because without having reference documentation of the platforms that they were targeting, it became a nightmare.

I would rate this solution as eight out of ten, because of the previous reasons that I gave around some of the features that are important for my clients. If it was not for that I would have given it a ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
PeerSpot user
Network Engineer with 11-50 employees
User
It has reduced the stress of collecting database event logs in silos from each database
Pros and Cons
  • "It has reduced the stress of collecting database event logs in silos from each database."
  • "Out-of-the-box policies ensure our compliance with standards like SOX, ISO 27001, and so on."
  • "The critical event alerts and reporting features have greatly reduced loss of man hours that would have been spent on going through the whole audit event logs."
  • "An easy, friendly user interface would be nice to have, since this would enable administrators to identify important events with a prompt response."

What is our primary use case?

It is used as a central audit repository and reporting for all my databases, which has reduced the stress of collecting database event logs in silos from each database.

How has it helped my organization?

Out-of-the-box policies ensure our compliance with standards like SOX, ISO 27001, and so on.

What is most valuable?

The critical event alerts and reporting features have greatly reduced loss of man hours that would have been spent on going through the whole audit event logs.

What needs improvement?

An easy, friendly user interface would be nice to have, since this would enable administrators to identify important events with a prompt response.

For how long have I used the solution?

Three to five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user489099 - PeerSpot reviewer
DB Admin with 5,001-10,000 employees
Real User
It monitors SQL traffic, looking for unauthorized or out-of-policy SQL statements.

What is most valuable?

AVDF can monitor SQL traffic to look for alerts on and prevent unauthorized or out-of-policy SQL statements. Because the final target of external attacks is SQL, it's very effective to check SQL level. In addition, this product transparently monitors the traffic; changing the applications is not necessary.

How has it helped my organization?

AVDF not only has an audit function, but it also has a database firewall function that protects the database, which is an important company asset, from external attacks typified by SQL injection. It supports a wide range of databases (Oracle Database, IBM DB2, Microsoft SQL Server and so on).

By integrating two major functions (auditing and database firewall)
into a single product, it became easier to use and the scope is really wide.

What needs improvement?

I would like to see a link-state tracking feature that quickly notices network failures. The benefit would be quick detection of network disconnection in DPE (inline) mode. If there is a network disconnection inline configuration, AVDF notices the network failure, but it cannot pass a link-state to the other side of the network (NIC). The problem currently is that handling of network failure cannot be performed correctly (depending on the point of failure).

For how long have I used the solution?

I have used it for around two years.

What do I think about the stability of the solution?

I actually encountered stability issues in DPE mode, but it was with the first release.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and technical support?

Technical support is now 8/10. For the first release, it was 5. It took time because technical support was dispatched to overseas teams using translation. Now, a local team can support the technical issues.

Which solution did I use previously and why did I switch?

We were using the audit product for memory reference types. We chose this product because of its integration with Oracle database and because it has the DB firewall function.

How was the initial setup?

Initial setup was not straightforward, because we should have considered the network environment when we decided the policy configuration. The complexity of AVDF depends on the system (network) environment. If the number of DBs to be protected is high, you should consider organizing the network environment.

What's my experience with pricing, setup cost, and licensing?

AVDF is very reasonable for Oracle products. The license cost is determined by the number of DB servers that will be protected. If you integrate the DB servers or use a multitenant environment, the number of licenses can also be aggregated.

Which other solutions did I evaluate?

Before choosing this product, I did not evaluate other options. Although there're some competitive third-party products for individual functions, as a comprehensive product, there are no other options.

What other advice do I have?

I recommend conducting a performance and availability test before implementing AVDF.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are an Oracle Platinum Partner.
PeerSpot user
it_user624783 - PeerSpot reviewer
Manager-Oracle Specialist at a tech vendor with 10,001+ employees
MSP
It provides reports that are directly related to the compliance issues.

What is most valuable?

Audit reporting and its user-friendliness that is required by auditors are valuable features.

How has it helped my organization?

It provides reports that are directly related to the compliance issues, i.e., for example SOX Compliance.

What needs improvement?

Policy defining should be more user-friendly. It still should be implemented and handed over to the end users. This policy defining cannot be done by an end user. It should be implemented initially, by a person who knows the Audit Vault along with the implementing business organization and their audit requirements. There should be a system analysis carried out and then this should be implemented. If the Oracle Audit Vault can give the administration interface to the end user itself, then he/she could generate the reports that they need, just by creating the customized report formats.

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

Some of the earlier versions have not matured enough.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

The technical support is good. I would give them a 7 out of 10 rating because there is no as such major implementation help given by the Oracle Support. There are a few people to support the same.

Which solution did I use previously and why did I switch?

It is easy to work with the Oracle ERP and Oracle Database.

How was the initial setup?

It is a little bit complex. The installation, implementation and policy defining should be done by experienced technical staff.

What's my experience with pricing, setup cost, and licensing?

You can use this as a good audit reporting tool and it is worth to use it as a high compliance risk tool.

What other advice do I have?

The installation and configurations should be done by experienced technical people, so as to achieve project success.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are Oracle Partners.
PeerSpot user