Analyzing Security Audit Journal
15 pts.
0
Q:
Analyzing Security Audit Journal
Hello, could you please tell me where can I find a book, guide or course about Tracking and Analizing Security Audit Journal on iSeries?  I have tried Appendix F on Security Guide but there are not all entries and it does not explain how to analize records in journal. 

Thanks a lot

Software/Hardware used:
iSeries V5R4
ASKED: Oct 22 2009  2:46 PM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
7990 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
I would start with understanding how to extract information from QAUDJRN, here are couple links to help:

http://systeminetwork.com/article/extracting-information-qaudjrn
http://publib.boulder.ibm.com/infocenter/iseries/v5r4/index.jsp?topic=/cl/cpyaudjrne.htm
http://systeminetwork.com/article/user-auditing-made-easier-addusraud-and-rmvusraud-commands

Now that you have your data, you can compare it to the values in Appendix F.

====================================================================

Appendix F of the Security Reference is the definitive guide to audit entries in QAUDJRN. If an entry isn't listed, you're using an out of date reference guide or IBM made a documentation error or you're processing entries that aren't audit entries (and probably shouldn't be processed.) And, come to think of it, an additional possibility is an entry type that was added by a PTF after the publication date of the reference guide. A PTF cover letter should indicate a location for documentation.

If IBM made a documentation error, report it to them. They might point you to additional documentation. (I'd be surprised if you found an entry that they haven't already covered.)

If you're using an older reference guide, download a current one.

If you're processing other entries (e.g., entries with journal codes other than 'T'), then you might be on your own.

What entry codes do you need help with? Or are they entries with entry code 'T' but that have entry types that you don't see in Appendix F?

Tom
Last Answered: Oct 22 2009  10:21 PM GMT by TomLiotta   7990 pts.
Latest Contributors: Whatis23   4040 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

Abigail   215 pts.  |   Oct 23 2009  2:38PM GMT

Another site I use most often:
 <a href="http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/advanced/tocView.jsp?view=toc&topic=/rzarl/rzarlf77.htm&topic=/rzarl/rzarlf77.htm" title="http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/advanced/tocView.jsp?view=toc&topic=/rzarl/rzarlf77.htm&topic=/rzarl/rzarlf77.htm" target="_blank">http://publib.boulder.ibm.com/infocenter…</a>

 

Fabypaumc   15 pts.  |   Nov 5 2009  5:10PM GMT

Hello,

Thanks for your answer.

The problem I have is that I am analizing DFU use, so I read “ZC” entries with program “QPDZDT”. Everytime I have analized, I have found that *FILE objects were edited, but now I have found this entries in *OUTQ objects and I do not know how to understand that there could be DFU use over *OUTQ objects .

 
0