Re: Audit trail for web application

From: Parag (parag_kulkarni_at_persistent.co.in)
Date: 06/21/05


Date: Tue, 21 Jun 2005 19:13:31 +0530

Hi,
    Thanks for the reply. Can you please tell me what are the best practices
that are followed in web application in .NET to implement the Audit trail ?
Is there any other way to implement it? It will be of greate help to me if
you could just point out what are the best practices to implement audit
trails for web applications.

Regards,
Parag

"bradley" <someone@microsoft.com> wrote in message
news:uKZVq7ldFHA.1504@TK2MSFTNGP15.phx.gbl...
> This is more of a SQL Server question than an ASP.NET question. The
> problem
> with implenting auditing at the application level or using table triggers
> is
> that it is very programming intensive and difficult to cover every point
> of
> database entry. Every time the data model changes, you would need to go
> back
> and revise the audit programming. Go to MSDN and read up on SQL Server
> Profiler. It can trap various events and output the log to a SQL Server
> table. There are also 3rd party database auditing tools that should do
> exactly what you need.
>
> "Parag" <parag_kulkarni@persistent.co.in> wrote in message
> news:OR4rFsidFHA.1456@TK2MSFTNGP15.phx.gbl...
>> Hello,
>> I have been assigned the task to design the audit trail for the ASP.NET
> web
>> application. I don't know what the best practices for such audit trails
> are.
>> Our application one dedicated user name and password to perform the
> database
>> operations. I need to capture all the operations which are performed on
> the
>> database. Also I need to able to capture the operations which directly
>> performed on the backend directly using the tools like enterprise
>> manager,
>> query analyzer, etc. And also the data for the action should be captured
> in
>> some set of tables, but not in the form of BLOB, so that if the admin
>> want
>> to know what are the various things the user did during the particular
>> session then that should be reproduced in the form of report. Does any
>> anybody have any idea of how to do such task? Any tips will be helpful.
>>
>> I am trying one approach with the help of triggers. But the problem with
>> this approach is that I am not able to store all the information need to
>> reproduce the same output if I try to generate report for the particular
>> session.
>>
>>
>>
>> Thanks and Regards,
>> Parag Kulkarni,
>> India
>> Email parag_kulkarni@persistent.co.in
>>
>>
>>
>
>



Relevant Pages

  • Re: Information Security
    ... Id like to assemble a toolkit both for gaining security control and ... Also pointers as to best practices and the like ... Shared logins are a big no-no, because they destroy your audit trail. ...
    (Security-Basics)
  • Re: Surrogate Keys: an Implementation Issue
    ... Consider a rollback database, or a ... database that must provide a complete audit trail of every change. ... One feature that would be high on my wish list would be the ability to expose system logs at an application level and further to preserve selected portions of them for long periods of time, eg., beyond checkpoints in some kind of system-supplied view. ...
    (comp.databases.theory)
  • Re: auditing with context?
    ... so it would seem that a generic method which jumps up on ... Its probably best implemented by doing all database updates through ... If you want to record context then this must must be ... Its also essential if the audit trail is ...
    (comp.lang.java.programmer)
  • Re: Difficult one :) - Logging changes in my database made
    ... I coppied your code and followed instructions on creating an audit trail ... when Itry to run it I get the error message ... I have a database where different users would be able to change the value ... txtUserName ...
    (microsoft.public.access.tablesdbdesign)
  • Re: auditing with context?
    ... Its probably best implemented by doing all database updates through stored procedures that generate the audit log while doing any auditable database operation. ... If you want to record context then this must must be passed as a parameter to every stored procedure that generates audit trail entries. ... If this is about code coverage, ...
    (comp.lang.java.programmer)