Forgot about event monitor. Thx. I think I've seen some statement event monitors with parameter markers and some with the actual values. I think it depends on the reopt option used? I'll need to take a look at it again.
I also found the following after posting my question:
"When you audit using the EXECUTE category, the statement text for both static and dynamic SQL is recorded, as are input parameter markers and
host variables. You can configure the EXECUTE category to be audited with or without input values."
IBM DB2 9.7 for Linux, UNIX and Windows Information Center
I don't know much about db2audit, but it sounds like this should do it.