We can auditing for sys operations by making the value of audit_sys_operations to TRUE. The sys audit logs will be stored at os level(audit_file_dest).
STEPS:
Check the values of audit_sys_operations
SQL> show parameter audit
NAME TYPE VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest string /oracle/app/oracle/admin/B2CRB
MD1/adump
audit_sys_operations boolean FALSE
audit_syslog_level string
audit_trail string DB
Enable audit for sys operations.
SQL>ALTER SYSTEM SET audit_sys_operations=true SCOPE=spfile;
system altered.
SQL> SHUTDOWN IMMEDIATE
SQL> STARTUP
SQL> show parameter audit
NAME TYPE VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest string /oracle/app/oracle/admin/B2CRB
MD1/adump
audit_sys_operations boolean TRUE
audit_syslog_level string
audit_trail string DB
You can check audit files at os level. ( /oracle/app/oracle/admin/B2CRBMD1/adump)
