Traditional (pre-Unified) Auditing
Survived, partially.
✓ certified by the mortician
In life
Traditional auditing is the pre-12c audit model: AUDIT and NOAUDIT statements, the AUDIT_TRAIL initialization parameter, records written to the SYS.AUD$ and FGA_LOG$ tables or to operating-system and XML files, and fine-grained audit policies managed through DBMS_FGA. Unified auditing, introduced in 12.1, replaced all of this with policy objects and a single audit trail.
Migrations care because audit configuration is usually compliance-driven and must be reproduced on the target. Knowing which statements, privileges and objects were audited, what conditions fine-grained policies applied, and where the records were written is needed to configure Azure SQL Auditing or the pgAudit extension. Databases running in mixed mode, with both traditional and unified auditing active, are harder to inventory.
Oracle's 21c Upgrade Guide declares traditional auditing deprecated (notice dated May 2021) and recommends unified auditing. The 26ai Upgrade Guide lists it as desupported (notice dated April 2023). The same 26ai page deprecates the PL/SQL cleanup helpers tied to the old trail and removes the FLUSH_UNIFIED_AUDIT_TRAIL procedure because unified records are now written directly to their table.
Cause of departure
Desupported in Oracle Database 26ai after deprecation in 21c. Oracle names Unified Auditing as the successor.
Obituary
Traditional (pre-Unified) Auditing, born before 11.2, recorded Oracle activity involving objects, privileges, and sessions. It distinguished success from failure and offered BY ACCESS or BY SESSION reporting.
Deprecated in 21c and desupported in 26ai, it leaves Oracle users with Unified Auditing. Its Azure heirs cannot fully match it: capture may be best-effort, and pgAudit cannot reliably audit superusers or reproduce mandatory SYSDBA auditing.
It is survived by Azure SQL Auditing, which lives on partly, and the pgAudit extension on PostgreSQL Flexible Server, which also lives on partly. Both require medium effort, a suitably restrained inheritance for a feature devoted to keeping records.
Survived by
Azure SQL Auditing partial effort M
Oracle AUDIT statements on objects, privileges and sessions map to Azure SQL audit action groups (batch completed, logins, schema changes, permission changes) written to Blob Storage, Log Analytics or Event Hubs. The granularity differs: Azure SQL audits statement and login events with optional predicate filters, whereas Oracle traditional auditing records per-object success or failure with BY ACCESS / BY SESSION options, and Azure SQL explicitly warns that capture is best-effort under heavy load.
- Export DBA_STMT_AUDIT_OPTS, DBA_PRIV_AUDIT_OPTS and DBA_OBJ_AUDIT_OPTS to see what is actually audited.
- Choose server-level or database-level auditing (database-level for busy multi-database servers).
- Map each Oracle audit option to action groups; on Managed Instance create server and database audit specifications with T-SQL.
- Send logs to Log Analytics for querying and to immutable Blob Storage for retention.
- Validate that failed Entra logins are reviewed in Entra sign-in logs, not the SQL audit.
Complications
pgAudit extension (PostgreSQL Flexible Server) partial effort M
pgAudit reproduces statement-class auditing (reads, writes, DDL, role changes, function calls) and object-level auditing through grants to an audit role, which covers most AUDIT ... BY ACCESS use cases. It writes to the server log rather than a table, cannot reliably audit superusers, is best-effort, and has no equivalent of Oracle's session-level aggregation or the SYS.AUD$ retention tooling.
- Allowlist pgaudit, add it to shared_preload_libraries and create the extension in each audited database.
- Set pgaudit.log to the needed classes (listing each class explicitly, since the minus shorthand is rejected on Flexible Server).
- For object auditing, create an audit role, grant it the audited privileges and set pgaudit.role.
- Enable PostgreSQL diagnostic settings so AUDIT: lines reach Log Analytics, Storage or Event Hubs.
- Document parameter values, because a major version upgrade recreates pgaudit without them.
Complications
Notices of correction
- oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 21c) · Upgrade Guide 21c, F17069-48, Feb 2026 · read 2026-09-26
- oracle Oracle Database Changes, Desupports, and Deprecations (Upgrade Guide 26ai) · Upgrade Guide 26ai, G43570-12, updated Jul 2026 · read 2026-09-26
- oracle Topics for Database Administrators and Developers (Database Concepts 19c) · Database Concepts 19c, E96138-11, Sep 2025 · read 2026-09-26
- microsoft Auditing for Azure SQL Database and Azure Synapse Analytics · page updated 2026-09-17 · read 2026-09-26
- microsoft Configure auditing for Azure SQL Managed Instance · page updated 2026-07-28 · read 2026-09-26
- microsoft Audit logging in Azure Database for PostgreSQL flexible server (pgaudit) · page updated 2026-07-16 · read 2026-09-26
- community pgAudit README · pgaudit branches per PostgreSQL 14-19 · read 2026-09-26