We can auditing for sys operations by making the value of audit_sys_operations to TRUE. The sys audit logs will be stored at os level(audit_file_dest).

STEPS:

Check the values of audit_sys_operations

SQL> show parameter audit

NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest                      string      /oracle/app/oracle/admin/B2CRB
                                                 MD1/adump
audit_sys_operations                 boolean     FALSE
audit_syslog_level                   string
audit_trail                          string      DB

Enable audit for sys operations.

SQL>ALTER SYSTEM SET audit_sys_operations=true SCOPE=spfile;

system altered.

SQL> SHUTDOWN IMMEDIATE

SQL> STARTUP


SQL> show parameter audit



NAME                                 TYPE        VALUE
------------------------------------ ----------- ------------------------------
audit_file_dest                      string      /oracle/app/oracle/admin/B2CRB
                                                 MD1/adump
audit_sys_operations                 boolean     TRUE
audit_syslog_level                   string
audit_trail                          string      DB

You can check audit files at os level. ( /oracle/app/oracle/admin/B2CRBMD1/adump)