Safeguard Audit Service Manual (G06.29+, H06.08+, J06.03+)
Specifying Auditing
Safeguard Audit Service Manual — 520480-031
2 - 29
Systemwide Device Auditing
The INFO SAFEGUARD command is enhanced to accept an additional option type
called COMPARE. The first four characters of the COMPARE namely COMP is used
as an abbreviation on the command line.
=INFO SAFEGUARD, COMP
The COMPARE option works in conjunction with the existing options. If this option is
provided, it results in displaying all those attributes that are already selected as a result
of the other provided options namely GENERAL, AUDIT, DETAIL, CI and display along
with the default values of each of those attributes.
Systemwide Device Auditing
You can configure systemwide auditing of all nondisk devices regardless of individual
device authorization records. Devices can be audited at the LOCAL level, the REMOTE
level, or both levels (ALL).
These configuration attributes control systemwide device auditing:
AUDIT-DEVICE-ACCESS-PASS
specifies conditions for auditing successful attempts to access any device or
subdevice on the system. This setting supplements individual device or subdevice
audit settings. The conditions can be ALL, NONE, LOCAL, or REMOTE. The default is
NONE.
If client auditing is enabled, this attribute also controls auditing for successful
file-system operations pertaining to devices and subdevices.
Note.
1. The Safeguard attribute, AUDI
T-CLIENT-GUARDIAN, is a synonym for
AUDIT-CLIENT-SERVICE. The AUDIT-CLIENT-OSS attribute is supported only on systems
running G06.29 and later G-series RVUs and H06.08 and later H-series RVUs.
2. The AUD
IT-DISKFILE-PRIV-LOGON attribute is supported only on systems running
H06.11 and later H-series RVUs and G06.32 and later G-series RVUs.
3. The attributes, AUDIT-EXCLUDE-FIELD and AUDIT-EX
CLUDE-VALUE , are supported
only on systems running J06.03 and later J-series RVUs, H06.14 and later H-series RVUs, and
G06.32 and later G-series RVUs.
4. The
AUDIT-OSS-FILTER attribute is supported only on systems running J06.04 and later J-
series RVUs and H06.15 and later H-series RVUs and G06.32 and later G-series RVUs.
5. The
AUDIT-TACL-LOGOFF attribute is supported only on systems running J06.08 and later J-
series RVUs and H06.19 and later H-series RVUs and G06.32 and later G-series RVUs.
6. The
DYNAMIC-PROC-UPDATE attribute is supported on systems running J06.10 and later J-
series RVUs and H06.21 and later H-series RVUs.
Note. The COMPARE option is supported on systems running J06.14 and later J-series RVUs
an
d H06.25 and later H-series RVUs.