XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 7. Safeguard Selection Criteria
XYPRO Technology Corporation 141 Proprietary and Confidential
7.4 Safeguard MessageIDs
Each Safeguard event generates a primary record and zero-to-many secondary
records. These records are identified by the MESSAGEID.
Safeguard MessageIDs
Msg ID Record
Type
Description
51 Primary This record has useful info for just about everything except changes
to user and object Protection Records. If you want to alert on the
record that shows the parameter that was changed, use the 55 (after)
records.
52 Secondary All DISKFILE-PATTERN-related info goes in this record. Use this
MessageID to Filter out the uninformative secondary records.
Everything you need to report or alert on is contained in the Primary.
53 Secondary add/create. When you add a User or Protection Record, Safeguard
generates one 53 record per field in the Record. So when you add a
user, for example, there will be many type-53 secondary records. If
you just want to know that a User or Protection Record was added,
select the (51) Primary Record.
54 Secondary This is the “Before” secondary record of changes to a Protection or
User Record. XMA combines this with the after(55) so that all the
useful information is contained in a single record:
"Password History 2 to 10"
55 Secondary This is the Afterrecord of changes to a Protection or User record. It
is suppressed by XMA and combined with the ‘After’ (55) record so
that all the useful information is contained in a single record.
This record type is also used for LOGOFFs and the new filename for
the RENAME operation.
This record type is also used for the Subject-Creator information
when the ‘working’ userid is different from the SUBJECT userid
(PROGID’d programs, etc).
56 Secondary Delete there will be a 56 record for each individual field in the
record that was deleted. If you just want to know that a User or
Protection Record was deleted, select the (51) Primary Record.
57 Secondary Authentication-related secondary records.
Note: As of XSR release 2.23, MESSAGEID 54 records are also produced when
diskfiles with Safeguard Protection Records are accessed for READ. This
matches SAFEARTs output. Each field in the Protection Record will have a 54
secondary record. You will probably want to filter these out of the XMA
database. See Example 1 on page 139.
You can use the MESSAGEID to hand pick the record for an audit event that contains
the information of interest to you.