Safeguard Audit Service Manual (G06.24+, H06.03+)

Specifying Auditing
Safeguard Audit Service Manual520480-014
2-26
ALTER SAFEGUARD and STOP SAFEGUARD
Commands
ALTER SAFEGUARD and STOP SAFEGUARD Commands
All attempts to change the Safeguard configuration with the ALTER SAFEGUARD
command, whether successful or not, are automatically audited. For each attempt, one
primary audit record and two secondary audit records are written to the current audit
file. One secondary record contains an image of the Safeguard configuration record
before the attempt. The other secondary record contains an image of the Safeguard
configuration record showing the attempted change.
All attempts to issue the STOP SAFEGUARD command, whether successful or not,
are automatically audited. A primary audit record is generated for each attempt.
Audit Service Commands
Except for the execution of INFO commands, all attempts to execute audit service
commands are automatically audited. For each attempt, a primary audit record is
written to the current audit file. For each ADD AUDIT POOL or DELETE AUDIT POOL
command, one secondary audit record is also written. The secondary record contains
the image of the audit pool record associated with the attempt.
For each attempted ALTER AUDIT POOL command, two secondary audit records are
written to the current file. One contains the image of the audit pool record before the
attempt, and the other contains an image of the audit pool record showing the
attempted change.
For each attempted ALTER AUDIT SERVICE command, two secondary audit records
are written to the current file. One contains an image of the Safeguard configuration
record before the attempt, and the other contains an image of the Safeguard
configuration record showing the attempted change.
TERMINAL Commands
Except for the execution of the INFO TERMINAL command, all attempts to execute
TERMINAL commands are automatically audited. For each ADD TERMINAL or
DELETE TERMINAL command, one primary and one secondary audit record is written
to the current audit file. The secondary record contains the image of the terminal
definition record associated with the attempt.
For each ALTER TERMINAL command, one primary and two secondary audit records
are written to the current file. One secondary record contains the image of the terminal
definition record before the attempted change. The other secondary record contains an
image of the terminal definition record showing the attempted change.
EVENT-EXIT-PROCESS Commands
Except for the execution of the INFO EVENT-EXIT-PROCESS command, all attempts
to execute EVENT-EXIT-PROCESS commands are automatically audited. For an ADD
EVENT-EXIT-PROCESS or DELETE EVENT-EXIT-PROCESS command, one primary