Removing records from Journal Receiver

20 pts.
Tags:
Security
I am suspecting that someone may alters the journal receivers on my system. Is it possible for someone to remove a record out of a receiver?? If so would that leave a trace?? How would I find out??

Answer Wiki

Thanks. We'll let you know when a new response is added.

Hi,

It’s impossible to remove an individual entry in a journal receiver (in any case, I’ve never heard about that). The journal receiver is inalterable. But, maybe someone can detach & delete the receiver (if he have enough authorities, of course)In this case, you loose the informations contained in the receiver. But you can add an audit on those commands (CHGJRN + DLTJRNRCV) to check if it’s the case.

Discuss This Question:  

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following