Safeguard Audit Service Manual (G06.29+, H06.08+, J06.03+)

SAFEART Field Descriptions
Safeguard Audit Service Manual 520480-031
7 - 4
Primary Record Fields
Primary Record Fields
A primary audit record represents each audited security event. Table 7-1 describes the
fields in the primary audit record. Except where noted, you can use these fields in SET
WHERE commands.
Table 7-1. Primary Record Fields (page 1 of 4)
Field Name Field Type Description
Auditnumber Numeric Identifies an audited event in the security audit
poo
l. For events whose descriptions span more
than one record, the records involved are linked
by a common value of Auditnumber. You cannot
use this field in SET WHERE commands.
CreatorAuthlocName Character Specifies the system name of the client or
su
bsystem that reported the audited event. This
field is blank if the system is remote.
CreatorAuthlocNumber System
number
Specifies the system number of the client or
su
bsystem that reported the audited event. For
the remote system, this field is -1 if the system is
running H06.26/J06.15 and later RVUs and zero
if the system is running earlier RVUs.
CreatorCreatorName Character Specifies the user name associated with the
Creato
r Access ID (CAID) of the client or
subsystem that reported the audited event.
CreatorCreatorNumber User number Specifies the CAID of the client or subsystem
tha
t reported the audited event.
CreatorProcessName Character Specifies the process name of the client or
su
bsystem that reported the audited event.
Safeguard events are indicated by a
CreatorProcessName of $ZSMP or $ZS00
through $ZS15.
CreatorSystemName Character Specifies the system name of the client or
su
bsystem that reported the audited event.
CreatorSystemNumber System
number
Specifies the system number of the client or
su
bsystem that reported the audited event.
CreatorTerminalName Character Specifies the terminal name of the client or
su
bsystem that reported the audited event. If
this value is not available, the field is set to all
blanks.
CreatorUserName Character Specifies either the group name.mem
ber
name or the alias of the process associated with
the client or subsystem that reported the audited
event.