Safeguard Audit Service Manual (G06.24+, H06.03+)
SAFEART Field Descriptions
Safeguard Audit Service Manual—520480-014
7-3
Primary Record Fields
Primary Record Fields
A primary audit record represents each audited security event. Table 7-1 describes the
fields in the primary audit record. Except where noted, you can use these fields in SET
WHERE commands.
Table 7-1. Primary Record Fields (page1of3)
Field Name Field Type Description
Auditnumber Numeric Identifies an audited event in the security audit
pool. For events whose descriptions span more
than one record, the records involved are linked
by a common value of Auditnumber. You cannot
use this field in SET WHERE commands.
CreatorAuthlocName Character Specifies the system name of the client or
subsystem that reported the audited event. This
field is blank if the system is remote.
CreatorAuthlocNumber System
number
Specifies the system number of the client or
subsystem that reported the audited event. This
field is zero if the system is remote.
CreatorCreatorName Character Specifies the user name associated with the
Creator Access ID (CAID) of the client or
subsystem that reported the audited event.
CreatorCreatorNumber User number Specifies the CAID of the client or subsystem
that reported the audited event.
CreatorProcessName Character Specifies the process name of the client or
subsystem that reported the audited event.
Safeguard events are indicated by a
CreatorProcessName of $ZSMP or $ZS00
through $ZS15.
CreatorSystemName Character Specifies the system name of the client or
subsystem that reported the audited event.
CreatorSystemNumber System
number
Specifies the system number of the client or
subsystem that reported the audited event.
CreatorTerminalName Character Specifies the terminal name of the client or
subsystem that reported the audited event. If
this value is not available, the field is set to all
blanks.
CreatorUserName Character Specifies either the group name.member
name or the alias of the process associated with
the client or subsystem that reported the audited
event.
CreatorUserNumber User number Specifies the group number, member
number of the process associated with the client
or subsystem that reported the audited event.