Database audit can strengthen the security of database. Logging database activities is usually the first step of implementing database audit. In this paper, we present a logging scheme for database audit. Unlike native database logging and auditing mechanism, our scheme is to monitor and log database activities through analyzing network traffic. The architecture of our scheme contains three principal components: packets capturing, packets parsing and data storage. First capture the packets to and from the database; then, by analyzing database communication protocols, parse the captured packets; finally, use the parsed results to support database audit.