Hello,
We integrated 10 tables of 1 DB (total 10 log source) with Oracle RDBMS Audit Record log source type (Oracle) with QRadar and often get "ORA-02391: exceeded simultaneous SESSIONS_PER_USER limit" error. As we know already, session limit defined by DBA and QRadar exceeded this limit.
We discussed this issue with DBA and they said that in the past QRadar simultaneously connected to DB and run queries on it and this resulted in problem in critical DB, that is why they had to set limit for user session.
They asked how Qradar connects to DB, which query it runs, does qradar close session after connection or create a session for each connection?
We ask these questions because we don't want any problem occur in our critical DBs. How many sessions for user are enough in DB side if we added 10 tables of 1 DB to QRadar?
Can you clarify the connection process of QRadar to Oracle RDBMS Audit Record?
------------------------------
Tahir Yagubov
------------------------------