sysmaster:syscrtadt
Posted in 2012
Topics: Error Codes & Troubleshooting, Security, Permissions & Auditing
we recently had to turn on auditing for a client which required auditing user "informix" for CRUD type transactions. After turning on auditing the audit trail files will now have two entries showing user informix inserting into the sysmaster:syscrtadt table at the same time the nightly level 0 starts; not sure why this is happening; I cannot select from this table to see exactly what is being inserted (158: ISAM error: Operation disallowed on SMI pseudo table.) Anyone with knowelege on why this table is being inserted into ? (There are no other entries in the audit trail file at the time the entries are made). 11.50.FC8 Mark
Hello.
According to our $INFORMIXDIR/etc/sysmaster.sql file, the description of this
table is regarding auditing operations, really:
{ C2 Audit call }
create table informix.syscrtadt { Internal Use Only }
(
event integer, { Event to audit }
result integer, { Success or Failure }
data char(256) { Additional data to audit }
)
It seems that your audit configuration is mistaken, have you started your
audit with informix user?
If not, is this user an AAO member??? It seems some other user is trying to
manipulate this table, or you might be hitting some defect.
Hope it helps.
Regards.
Alexandre Marini
IBM Informix Certified Professional v10 / v11.50 / v11.70
IBM Information Management Informix Technical Professional
IBM Infosphere DataStage Technical Professional
Database Administrator
> To: ids@iiug.org
> From: mark.jalkiewicz@verizon.net
> Subject: sysmaster:syscrtadt [27282]
> Date: Mon, 4 Jun 2012 14:15:11 -0400
>
> we recently had to turn on auditing for a client which required auditing user
> "informix" for CRUD type transactions. After turning on auditing the audit
> trail files will now have two entries showing user informix inserting into
the
> sysmaster:syscrtadt table at the same time the nightly level 0 starts;
> not sure why this is happening; I cannot select from this table to see
exactly
> what is being inserted (158: ISAM error: Operation disallowed on SMI pseudo
> table.)
>
> Anyone with knowelege on why this table is being inserted into ? (There are
no
> other entries in the audit trail file at the time the entries are made).
>
> 11.50.FC8
>
> Mark
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Hello,
For better understanding can you provide the Informix version and the
result of:
onaudit -c
onaudit -o -yid or id -a as user informix
ls -liad $INFORMIXDIR
Thanks
On Mon, Jun 4, 2012 at 7:15 PM, MARK JALKIEWICZ <mark.jalkiewicz@verizon.net
> wrote:
> we recently had to turn on auditing for a client which required auditing
> user
> "informix" for CRUD type transactions. After turning on auditing the audit
> trail files will now have two entries showing user informix inserting into
> the
> sysmaster:syscrtadt table at the same time the nightly level 0 starts;
> not sure why this is happening; I cannot select from this table to see
> exactly
> what is being inserted (158: ISAM error: Operation disallowed on SMI pseudo
> table.)
>
> Anyone with knowelege on why this table is being inserted into ? (There
> are no
> other entries in the audit trail file at the time the entries are made).
>
> 11.50.FC8
>
> Mark
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--00248c6a6726439ed504c1ab3e54