Try our new research platform with insights from 80,000+ expert users
it_user562536 - PeerSpot reviewer
Database & Flexcube System Administrator at a financial services firm with 501-1,000 employees
Vendor
Out-of-the-box reports covers most of the auditing features that you might need. In earlier versions, there were some configuration bugs.

What is most valuable?

The out-of-the-box reports feature is most valuable because it covers most of the useful auditing features that you might need.

How has it helped my organization?

I haven’t used this product at my current job but I implemented it at a couple of other organizations, as a technical consultant. What they really wanted to do was to be able to check who is doing what with their sensitive data and they achieved that.

What needs improvement?

I am not sure for the latest version but for previous versions, there were some configuration bugs when connecting Audit Vault Agent with Audit Vault Server.

For how long have I used the solution?

I have used this product for five years.

Buyer's Guide
Oracle Audit Vault
June 2025
Learn what your peers think about Oracle Audit Vault. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

What do I think about the stability of the solution?

If you use the DB AUD$ option, you have to be careful because this table might fill up your database without any notifications.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and support?

I would give the technical support a 7/10 rating.

Which solution did I use previously and why did I switch?

We previously did not use any other solution.

How was the initial setup?

The initial setup was a bit complex for versions 10-11. However, the setup for version 12 is straightforward.

What's my experience with pricing, setup cost, and licensing?

In my opinion, the license cost is worth the work that the product is doing.

Which other solutions did I evaluate?

I haven’t evaluated other options because there were only Oracle environments.

What other advice do I have?

If you are implementing this product, I would advise not to audit the whole database since that will cause you a lot of trouble. You need to plan very well of what needs to be audited.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user560259 - PeerSpot reviewer
IT Solutions Architect at a tech services company with 51-200 employees
Real User
The PL/SQL auditing feature helps to control code updates. In data-sensitive environments, leveraging the inbuilt compliance reports can be valuable.

What is most valuable?

The most valuable features of this product are:

  • PL/SQL auditing: It helps to control the code updates in a sensitive environment.

  • Inbuilt compliance reports - In data-sensitive environments where auditing teams require generation of reports for specific database such as SOX-compliant financial databases, HIPAA-compliant healthcare databases or PCI-compliant databases, leveraging these inbuilt reports in Oracle Audit Vault 12c can be of great value.

How has it helped my organization?

We are the implementers of the product to our clients.

What needs improvement?

This product should improve capturing more auditing information for database sessions that connect via applications and also through database links. When the database sessions are generated from the applications that use database links from other databases, by nature the target database won't capture relevant information of the remote sessions. Also in the audit trails, it is of utmost importance who are the data consumers so as to track and control the appropriate use of the information.

There is need to improve capturing of more auditing information for OS logins as well.

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

I have not encountered any stability issues.

What do I think about the scalability of the solution?

I have not encountered any scalability issues.

How are customer service and technical support?

I would give the technical support a 7/10, i.e., an above-average rating.

Which solution did I use previously and why did I switch?

We have not used any other solution.

How was the initial setup?

The setup for Audit Vault is relatively simple.

However, configuring personalized reports is a nasty task. There are many variables involved and the documentation is not very good. The way the reports can be personalized must be more visual and requires a drag-and-drop feature rather than creating it in a rudimentary manner.

What's my experience with pricing, setup cost, and licensing?

It is an expensive solution. For those customers who do not have any ULA agreements with Oracle, the solution is practically impossible to acquire.

Which other solutions did I evaluate?

We did not evaluate other options.

What other advice do I have?

Those who have already acquired the product, the implementation and use of the product is dependent on its daily use so as to get acquainted with all the features. If they have installed the platform and don't use it regularly, it’s a waste of time and energy.

One day when somebody asks about the audit reports, the database auditors will be in a big problem if they don't know how to generate the requested reports.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are Oracle GOLD Partners.
PeerSpot user
Buyer's Guide
Oracle Audit Vault
June 2025
Learn what your peers think about Oracle Audit Vault. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
it_user427872 - PeerSpot reviewer
Sr. Lead Consultant - Database at a tech company with 501-1,000 employees
Vendor
The REDO_COLL function captures all changed values in the audited tables of a database.

What is most valuable?

The most valuable features of this product are auditing the old and new values after each change in the database, REDO_COLL and capturing application context functionalities.

REDO_COLL is a function provided by Oracle Audit Vault where the system captures all values that are changed in the audited tables of a database. So if someone fires an update in a table, the auditing system will not only capture the value which was enforced as part of the update, but will also capture the old value (before the update was done).

Application Context is an interesting implementation, where we can pass additional information about front-desk application users in the audit trail. So, when we look at an audit log we not only see the database user but also the application user who has viewed/changed the data.

How has it helped my organization?

Auditing as an imperative function of any Enterprise company. We require the audit logs for compliance needs and for tighter control of the infrastructure. Being in the Health Insurance industry and handling PHI & PII data, there are compliance mandates enforced by HIPAA. Oracle audit Vault helps us implement the control points enlisted under "Audit Requirements". HIPAA mandates us to track any/all access to ePHI data in our system, even if it is just a READ ONLY access. With Oracle Audit Vault, we have a centralized system to access all Audit Trails for sensitive data access.

What needs improvement?

The price factor makes it “out of reach" for small players in the IT industry. Even the SaaS model is very expensive. SaaS is an alternative hosting model where Oracle hosts the audit vault in their data center and installs audit collection agents on client data center. They host these appliances in their HIPAA-complaint data center where all controls are active. They work with the client to set-up secure channels for audit data and then sign BAA with the client. This auditing feature is made available as a service for which Oracle charges on a pro-rated basis.

Also, Audit Vault is not yet licensed to run with Other Cloud offerings like Amazon AWS, which makes it difficult to implement incase your existing tech-stack is on AWS or any other non-Oracle-Cloud Infrastructure.

For how long have I used the solution?

I have used this product for almost a year.

What was my experience with deployment of the solution?

Yes, its not certified to run with Amazon AWS.

What do I think about the stability of the solution?

I did not encounter any such issues. The product was both stable and scalable.

What do I think about the scalability of the solution?

I did not encounter any scalability issues either.

How are customer service and technical support?

The technical support is great.

Which solution did I use previously and why did I switch?

We did not use any other solutions. Our company needed a full auditing suite for our database along with capturing application context and REDO_COLL functionality. This product was our first choice.

How was the initial setup?

It has an appliance setup which is not supported on Amazon or any other third party cloud, making the process very cumbersome.

What's my experience with pricing, setup cost, and licensing?

The pricing policy is quite aggressive. We must equal the number of processors on DB in accordance with this appliance, thus making it very expensive.

Which other solutions did I evaluate?

We evaluated the IBM Guardium solution.

What other advice do I have?

If this product falls under your budget, then there is nothing like it in the market.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1221 - PeerSpot reviewer
Database Expert at a tech company with 51-200 employees
Real User
Great Oracle Database Security Management Tool, minimal processing overhead and great GUI .

Valuable Features:

Audit Vault is a good Oracle Tool to collect all Database Audit Information in a single database repository for managing Database Security. I have used it to collect DB login info , Server access info, SQL statements , before and after images of Data using OS, DB and REDO collectors. Provides and easy to use browser based GUI to generate Standard Reports for Compliance purposes - SOX(Sabanes Oxley) and PCI(Payment Card Industry) compliance and allows custom report generation too.

Room for Improvement:

The underlying Mechanism for collect SQL statements (REDO collector) is still based on Oracle Streams technology. Data in Audit Vault needs to Selected properly and purged at regular intervals else it grows too much to manage. Increases network traffic especially between Audit Vault Server and Source Databases.

Other Advice:

DBA skills needed for proper setup. Also, there are situations when the DBA needs to run Oracle streams commands to manage the streams data flows and also monitor Streams propagation and apply activities. Next release probably will use Golden Gate as the underlying technology instead of Streams.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user4401 - PeerSpot reviewer
it_user4401Developer at a transportation company with 1,001-5,000 employees
Vendor

It is very useful for many companies because it provides standard audit assessment reports covering, privileged users, account management roles and privileges, object management and system management across the enterprise.