# Ingesting Oracle's Audit Trail

**URL:** <https://discuss.elastic.co/t/ingesting-oracles-audit-trail/259897>\
**Category:** Logstash\
**Created:** [December 30, 2020, 3:52pm UTC](https://discuss.elastic.co/t/ingesting-oracles-audit-trail/259897 "2020-12-30T15:52:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [December 30, 2020, 3:52pm UTC](https://discuss.elastic.co/t/ingesting-oracles-audit-trail/259897/1 "2020-12-30T15:52:42Z")

</div>

Hi, I'm ingesting the content from sys.dba\_audit\_trail into ES using the jdbc input plugin.  
Everything goes ok with the exception of the field transactionid which is of type (at db level of RAW(8))  
Here an example  
000F001A00008F0A

When trying to index to ES I have the following error

`[2020-12-30T15:55:03,988][ERROR][logstash.outputs.elasticsearch][oracle][e165fba9d3a72fb12f1b528141425a306cab12e7399f0edbe76920a85722dc89] An unknown error occurred sending a bulk request to Elasticsearch. We will retry indefinitely {:error_message=>"\"\\xB2\" from ASCII-8BIT to UTF-8",`

I've tried with diferent values of

`columns_charset => {"transactionid" => "xxx"}`

and I have the event indexed without errors but with unreadable values

What Am I missing?  
Thank you!  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 5, 2021, 12:44am UTC](https://discuss.elastic.co/t/ingesting-oracles-audit-trail/259897/2 "2021-01-05T00:44:04Z")

</div>

Is there anything in the Elasticsearch logs at the time that would correlate?

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [January 5, 2021, 6:29am UTC](https://discuss.elastic.co/t/ingesting-oracles-audit-trail/259897/3 "2021-01-05T06:29:17Z")

</div>

Hi Mark,  
I couldn't find anything at elastic's logs.  
This type at Oracle level are a raw representation using for example to store files. I don't know why they are using it to represent the transaction id.  
I found a workaround that is to convert to hex the raw representation. Something like this in the `select` statement from jdbc input pluging

` select entryid,os_username,username,userhost....,`**`RawToHex(transactionid)`** ` from dba_audit_trail`

Thank you!  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2021, 6:29am UTC](https://discuss.elastic.co/t/ingesting-oracles-audit-trail/259897/4 "2021-02-02T06:29:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
