Objective: Explain the Enterprise Manager web architecture and identify the prerequisites for securely accessing its console and managing supported Oracle AI Database 26ai targets.
Oracle Enterprise Manager 24ai provides a browser-based console for centralized monitoring and administration. Administrators use it to inspect supported databases and hosts, review monitored conditions, and run authorized management operations. The console is already a web application; it does not need to be converted into one.
Enterprise Manager 24ai and Oracle AI Database 26ai are separate products with separate release numbers. A database installation does not automatically provide a Cloud Control management deployment. Enterprise Manager can manage supported on-premises, cloud, and hybrid environments; hosting it on Oracle Cloud Infrastructure (OCI) is an option rather than a requirement.
Oracle Enterprise Manager Database Express (EM Express) is desupported in Oracle AI Database 26ai. Older instructions for enabling an embedded database console through XDB ports are therefore not the setup procedure for this module. Here, the browser connects to the Enterprise Manager management infrastructure.
| Component | Responsibility |
|---|---|
| Browser console | Presents management pages to an authenticated Enterprise Manager administrator. |
| Oracle Management Service (OMS) | Provides the management application, processes information from agents, and coordinates operations. |
| Oracle Management Repository | Stores management configuration and information in a supported Oracle database. |
| Oracle Management Agent | Monitors configured targets and performs supported management work on the managed host. |
| Management plug-ins | Provide capabilities for particular target types, including Oracle Database. |
Administrators interact with the console, while agents collect target information and communicate with OMS. OMS uses the repository to maintain management data. Browser access and agent communication use separate network paths that must both be configured appropriately.
A managed target does not have to reside on the OMS host. The repository also has a different purpose from an application's business database: it holds Enterprise Manager's management information. Repository availability is a dependency of the management system.
Obtain the published HTTPS console URL from the Enterprise Manager administrator or installation records. Its general form is:
https://<management-host>:<console-https-port>/em
Replace both placeholders with the configured values. A deployment may publish a load-balancer address rather than an individual OMS hostname. The browser console port is distinct from the agent upload port and the WebLogic administration endpoint. Do not assume that an old EM Express URL identifies this console.
An authorized administrator on the OMS host can inspect the configuration using the OMS installation's emctl executable. This example is an operating-system command, not SQL:
# Replace the path with the actual OMS home.
/path/to/oms_home/bin/emctl status oms -details
Run it using the authorized OMS software-owner account and respond securely to any credential prompt. The output includes status and console address information. Use the deployment's published endpoint when a front-end address differs from the individual OMS address.
A console login is different from a database SYSDBA connection. Enterprise Manager roles and target privileges determine what the administrator can see and do. Successful sign-in does not grant unrestricted access to every managed system.
Before adding a target, verify the supported combination of Enterprise Manager release update, database plug-in, agent, database release, and operating system. Feature support can vary by update. Certification of a database as a managed target does not establish certification of that same release as the management repository.
Preparing a target generally involves these activities:
CDBs, PDBs, listeners, and hosts have distinct monitoring contexts. Verify which targets were discovered and configured rather than assuming that adding a database completes every related target setup. Some management capabilities require appropriate licenses or management packs.
The administrator account identifies the person using Enterprise Manager. Monitoring credentials allow collection of information from a target. Job credentials authorize a particular database or host operation. These purposes may require different accounts and privileges.
Named credentials let Enterprise Manager store reusable credential definitions with controlled access. Configure their ownership and permitted use according to the intended operation. A monitoring account should not receive broad administrative privileges merely because a separate maintenance job needs them.
For an initial job, choose a supported information-gathering task on a test target. Check the target, credentials, schedule, and required privileges before submitting it, then review completion status and output. An Enterprise Manager job and a database DBMS_SCHEDULER job are separate mechanisms, even when both schedule administrative work.
A metric measures a monitored condition. Thresholds identify conditions that warrant attention. For example, a tablespace-space metric may cross a configured warning threshold. The resulting event can be processed by an incident rule that creates or manages an incident and notifies the responsible administrator.
Choose thresholds that fit the workload and metric definition. Investigate capacity, growth, and available storage rather than assuming that every space warning requires the same action. An incident provides a way to track the response; it does not itself resolve the underlying condition.
Email notifications require mail-service configuration, recipient details, and applicable rules or schedules. Test mail delivery separately from the rule that selects events for notification. Creating a database user or OS job account does not configure email delivery.
Planned maintenance can use appropriately configured blackouts or notification blackouts. Their effects differ, so select the required monitoring and notification behavior deliberately. Metric alerts are not row-level auditing or a mechanism that automatically emails every change to business data.
When the console is unreachable, check the published address, DNS, routing, permitted network access, certificate trust, OMS health, and repository dependencies. A database listener command does not start OMS, and a target database restart is not a general remedy for a browser connection problem.
If the console works but target data is stale, inspect agent health, communication, collection errors, and monitoring credentials. If monitoring works but email is missing, inspect rule selection and the notification delivery path.
A target database can be down while the management console remains accessible. Conversely, an inaccessible console does not prove that the target database is down. Diagnose the affected component before following the site's approved restart or recovery procedure.
By the end of this module, you should be able to:
The next lesson examines the prerequisites and access configuration for the Enterprise Manager browser console.