Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Configuration
Safeguard Administrator’s Manual523317-013
9-18
Configuring Client Auditing
AUDIT-OBJECT-MANAGE-PASS
Successful attempts to create or manage authorization records for any system
object are audited. This setting supplements the audit settings for the individual
objects. The conditions can be ALL, NONE, LOCAL, or REMOTE. The default is
NONE.
AUDIT-OBJECT-MANAGE-FAIL
Unsuccessful attempts to create or manage authorization records for any system
object are audited. This setting supplements the audit settings for the individual
objects. The conditions can be ALL, NONE, LOCAL, or REMOTE. The default is
NONE.
To change any of these values, issue the ALTER SAFEGUARD command from
SAFECOM. For example, to audit all successful attempts to manage an authorization
record for any system object:
=ALTER SAFEGUARD, AUDIT-OBJECT-MANAGE-PASS ALL
Configuring Client Auditing
You can configure the Safeguard software so that it does not accept audit records from
privileged clients. If your site has no interest in client audit records, you can use this
feature to reduce the quantity of audit records written to the Safeguard audit files.
These Safeguard attributes control client auditing:
AUDIT-CLIENT-GUARDIAN
ON specifies that the Safeguard software will accept guardian related audit records
from privileged client subsystems and write those records in the Safeguard audit
files. OFF specifies that the Safeguard software will not accept client guardian
related audit records. The initial value is ON.
AUDIT-CLIENT-OSS
ON specifies that the Safeguard software will accept OSS related audit records
from privileged client subsystems and write those records in the Safeguard audit
files. OFF specifies that the Safeguard software will not accept client OSS related
audit records. The initial value is ON.
For more information about client subsystem auditing, see the Safeguard Audit Service
Manual.
Caution. Configuring the Safeguard software to audit all system objects might cause system
performance problems. Be sure you have adequate system resources to handle extensive
auditing.
Note. The AUDIT-CLIENT-GUARDIAN and AUDIT-CLIENT-OSS attributes are supported only
on systems running G06.29 and later G-series RVUs and H06.08 and later H-series RVUs.