AVDF is licensed on the targets you monitor, not the appliances that do the monitoring, and that single distinction is where most buyers overspend. This guide shows you exactly what to count, what is bundled for free, and where your leverage sits before you sign.
AVDF is licensed on the targets you monitor, not the appliances that do the monitoring, and that single distinction is where most buyers overspend. This guide shows you exactly what to count, what is bundled for free, and where your leverage sits before you sign.
Oracle Audit Vault and Database Firewall (AVDF) is sold as a single product built from two components: Audit Vault (a detective control that collects and consolidates audit data) and Database Firewall (an inline or out-of-band SQL traffic monitor). You do not license these separately. Per Oracle's AVDF Licensing Information for Release 20 (updated September 2, 2025), the licensing dimensions are the targets you monitor, the number of processors on the computers where those targets sit, and the number of named users of those targets.
The metric that matters is measured on the target side, not the AVDF side. The Oracle Technology Global Price List (April 16, 2026) states plainly that only the processors of the sources which are protected, monitored, or audited must be counted. AVDF is priced on the two standard technology metrics, Processor and Named User Plus (NUP), exactly like the Oracle Database EE options you already know. The complication is not the metric, it is knowing what to count. In 25 years of reviewing these deals, the single most common error we see is a buyer who counts AVDF appliances or total database estate rather than the specific monitored population.
You license the databases you watch, not the machines doing the watching. Confuse the two and you buy licenses Oracle never asked you to buy.
This is the point buyers most often miss, and it always costs money. Oracle's AVDF Licensing Information (Release 12.2) is explicit: there is no separate license fee for the servers where AVDF is installed, and you can deploy multiple Audit Vault and Database Firewall servers for high availability or network topology purposes without any impact to the license, as long as the number of secured target processors remains the same.
The practical consequence is significant. You can stand up two Audit Vault servers for high availability, add Database Firewall nodes across network segments, and scale the collection tier as your topology demands, all with zero additional license cost. The number you pay for is the count of monitored target processors (or target named users), full stop. If a reseller or an Oracle account rep quotes you against the size or count of the AVDF appliances, that is a misread of the model and a signal to push back hard.
The appliance is also a self-contained software stack. Oracle Linux and Oracle Database 19c Enterprise Edition are installed as part of AVDF, but the embedded database is restricted-use: it is limited to Partitioning, Advanced Security, Advanced Compression, Database Vault, and In-Memory options, purely to run the AVDF repository. You owe no separate Database EE license for it. Monitoring the appliance's own embedded database via a shadow Audit Vault server also carries no additional AVDF fee (Release 20, September 2, 2025).
AVDF ships with several restricted-use licenses baked in. Knowing they exist prevents you from buying full-use versions you do not need, and prevents Oracle from double-charging in a bundled proposal.
| Bundled component | What the restricted use covers | When you owe a full-use license |
|---|---|---|
| Oracle Database 19c EE (repository) | Runs the AVDF audit repository with a fixed set of options (Partitioning, Advanced Security, Advanced Compression, Database Vault, In-Memory) | Never, for AVDF repository use. Any other database workload on that box is unlicensed. |
| BI Publisher | Publishing and viewing included AVDF reports; layout changes and modified reports against the unchanged schema | Any BI Publisher use beyond the AVDF reporting scope |
| Data Masking and Subsetting (Application Data Modeling) | Restricted-use features within AVDF | Any masking or subsetting use outside AVDF's restricted scope |
| SQL Firewall | Included for Oracle databases being monitored under AVDF (Release 20) | Not applicable when used with AVDF on supported editions |
The SQL Firewall inclusion is a genuine 2025-era improvement worth confirming in writing. It means monitored Oracle databases get SQL Firewall coverage inside your AVDF entitlement rather than as a separate line item. If any of these bundled components appear as priced additions in your quote, strike them and cite the Release 20 Licensing Information document by name.
Four restricted-use entitlements ship inside AVDF. Every one of them is a line a vendor rep can accidentally, or conveniently, re-quote at full price.
Real Application Clusters is the single most reliable way to under-scope or over-scope an AVDF deal. Oracle's rule (Release 20, September 2, 2025) is that in a RAC environment, every node on the target must be licensed. This means one logical database presented to the business is not one license unit if it runs across three cluster nodes; it is three sets of node processors, subject to core-factor math.
Two failure modes follow, and they run in opposite directions. First, under-counting: a buyer records the monitored estate as "12 databases" without noticing that several are RAC clusters, then fails an audit because the node math was never done. Second, over-counting: a buyer licenses every node in a cluster including standby or idle nodes that are not actually collecting audit data or passing SQL traffic through the firewall. Both are expensive, in different currencies. The under-count costs you an audit finding and back-support; the over-count costs you cash every year at 22 percent support.
The discipline is straightforward but rarely applied: for every RAC target, document which nodes are actually monitored, apply the core factor per node, and round up per node as required. If you run Oracle databases in cloud environments or virtualized estates, the counting rules layer on top of AVDF's target-side metric, so reconcile both before you commit.
AVDF offers the same two metrics as the rest of the technology stack: Processor and Named User Plus. Picking the wrong one is, in our audit-defense experience, the most common single driver of AVDF over-spend. The default reflex is Processor, because it removes the burden of counting users. But for a monitored target with a small, countable, and stable user population, NUP can be materially cheaper. The reverse is equally true: for a high-user or internet-facing target, Processor is almost always the correct and cheaper metric.
For AVDF NUP, only users of the monitored sources count, per the Technology Global Price List (April 16, 2026). Note the NUP minimums that apply on the database metric generally: 25 NUP per processor for Enterprise Edition and 10 per server for SE2. A 16-core Intel server (core factor 0.5) under NUP would require 16 x 0.5 x 25 = 200 NUP at list even if you have fewer real users. That minimum is exactly why NUP is not automatically the cheap option; run both calculations per target before you decide.
Processor counting uses the standard core-factor math. A server with 6 cores and a core factor of 0.25 needs 2 processor licenses (6 x 0.25 = 1.50, rounded up to 2). For Standard Edition targets the counting differs: a processor is treated as an occupied socket, and each chip in a multi-chip module counts as one socket. These rules are identical to the ones in our Oracle Database licensing guide, so if you have already modeled your estate there, reuse that work.
AVDF list pricing is anchored to the Oracle Technology Global Price List. Treat list as Oracle's opening position, not a market price. Based on Redress Compliance's Oracle Technology Price List analysis (May 21, 2026), enterprise customers typically negotiate 40 to 70 percent below list on technology products, with database-family discounts of 50 to 80 percent off list common on first purchase. There is no reason AVDF should land at the shallow end of that band if you have any deal size or competitive alternative.
For a directional benchmark from a sibling security product, a 16-processor Database Vault deployment lists at $11,500 per processor (Redress Compliance, February 25, 2025). We cite this only as a reference point drawn from market experience; AVDF has its own list price and its own licensing model, unrelated to Database Vault. The two products are frequently confused at purchase, so be precise: Database Vault is a preventive control (it blocks privileged access), while AVDF is a detective control (it records and alerts). Buying one when you needed the other is a scoping failure, not a pricing failure, and it is not fixable by discount.
| Cost element | Rule of thumb | Buyer action |
|---|---|---|
| List price | Opening position only | Never accept; benchmark against band below |
| Discount band | 40 to 70 percent off list (market experience) | Target the upper end with volume or a credible alternative |
| Annual support | 22 percent of net license fees, and it rarely falls | Minimize net license count now; support compounds forever |
| Core factor | 0.5 typical for x86; 0.25 for some chips | Apply per node, round up per node |
The long-run cost is support, not the initial license. Support runs at 22 percent of net license fees per year and almost never falls, even when your usage shrinks. This is why over-purchasing AVDF processors against an inflated target count is not a one-time waste; it is an annuity paid to Oracle for the life of the contract. Every processor you buy but do not need costs you roughly 22 percent of its net price every single year.
Support at 22 percent of net fees is an annuity. An over-scoped AVDF purchase is not a mistake you make once; it is a bill you pay forever.
AVDF is architected to monitor hundreds or thousands of targets, which is precisely what makes over-licensing so easy. The scale of the platform invites buyers to license the whole estate "to be safe." Resist it. You license what you monitor, and you can grow the monitored population later. Here is where the money leaks:
The remedy is a documented, target-by-target inventory produced before you negotiate, not after. For each monitored source, record: is it Oracle or a third-party database (SQL Server 2019/2022, PostgreSQL 12-15, MongoDB 4.4/5.0, and others are supported in current 20.x releases), is it RAC and how many nodes are monitored, what is the core count and core factor, and what is the realistic user population. That inventory is your licensing position and your audit defense in the same document. If AVDF is enabled without the corresponding entitlement, you have the same exposure profile described in our note on accidentally enabled security options, so treat configuration state and license state as one reconciliation.
AVDF sits inside the broader security options family alongside Database Vault and Advanced Security with TDE. If you are building a compliance program rather than solving a point requirement, model the whole family together using the database security options licensing overview before you commit to any single product. Buying these piecemeal, at separate times, with separate discounts, is how estates end up over-licensed and under-negotiated.
Three moves protect you. First, produce the target inventory described above and license strictly to it, appliance count excluded. Second, run both Processor and NUP math per target and choose the cheaper metric with the minimums applied; do not let a rep pick for you. Third, negotiate against the 40 to 70 percent band and get the SQL Firewall inclusion and the restricted-use bundles confirmed in the ordering document, not just implied by a product page. If you are also modeling encryption or masking obligations, reconcile them against the encryption mandate strategy so you do not buy overlapping full-use options AVDF already covers at restricted use.
No. Oracle's AVDF Licensing Information states there is no separate license fee for the servers where AVDF is installed. You can deploy multiple Audit Vault and Database Firewall servers for high availability or network topology with no license impact, as long as the number of monitored target processors stays the same. You license the targets you monitor, not the appliances.
Every node on the target must be licensed. A single logical RAC database running across three nodes is three sets of node processors to count, subject to core-factor math and per-node rounding. License only the nodes actually monitored, and document them, because both under-counting (audit exposure) and over-counting standby nodes (wasted spend plus 22 percent annual support) are common and expensive.
In Release 20, use of SQL Firewall with AVDF is included for the Oracle databases being monitored, on the supported database editions. Confirm the specific edition support in Oracle's Database Licensing Information User Manual, and make sure the inclusion is reflected in your ordering document rather than quoted as a separate line item.
It depends on the monitored target. Processor is usually correct for high-user or internet-facing targets. NUP can be cheaper for small, countable, stable user populations, but the 25 NUP per processor minimum (10 per server for SE2) often erodes that saving. Run both calculations per target before choosing; the wrong metric is the most common driver of AVDF over-spend.
List is Oracle's opening position only. Enterprise customers typically negotiate 40 to 70 percent below list on technology products, with database-family discounts of 50 to 80 percent off list common on first purchase. Push toward the upper end of the band with volume or a credible alternative, and remember support runs at 22 percent of the net (discounted) fee every year.
No, and confusing them is a scoping error a discount cannot fix. Database Vault is a preventive control that blocks privileged access; AVDF is a detective control that records audit data and monitors SQL traffic. They have separate licensing models and separate list prices. Decide which control your requirement actually needs before you buy either.
The separately-licensed options and packs that ship enabled by default, get switched on with a single click, and become the single largest line item in most Oracle audit findings.
Gated with a work email on the download page. No sales follow up you did not ask for.
Get the White Paper →500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.