Re: how to enable auditing for all users?
Posted in 2006
Jonathan Leffler wrote:
> calyanram@hotmail.com wrote:
> > there are some external apps accessing my db. ok
> >
> > i am able to see the audit activities for the users who are
> > internally using the db, that is using dbaccess.
> >
> > but some VB apps, even nobody knows who are using it.accessing
> > this db.
> >
> > how to find those users?
>
> Well, this is not always as easy as you'd like. However, the obvious
> choice is to audit STSN - start session. So, ensure you have nothing in
> your _exclude mask; add STSN to your _default or _require mask (I
> suggest _require). Enable auditing.
>
> This should tell you who is starting the sessions. Depending on your
> system, it might tell you where the connection is coming from - that's
> why platform and version information can be significant.
Checking on my office machines, using IDS 10.00.UC3 on Solaris 8 (yes,
I need to upgrade too), the start session records include the hostname
(when resolvable - the I/P address when not resolvable, I believe but
have not verified).
I'm currently running with _exclude listing DLRW, INRW, RDRW, UPRW, and
_require listing everything else I can lay my hands on - and no per
user masks. It tracks my sessions pretty well.
...hmmm; with audit mode (ADTMODE) 7, it seems to be logging RDRW for
users...wonder what's up there...oh; a conflict between _require and
_exclude and _require seems to win...oh darn, the documentation says
otherwise (p1-7ff in TFM - which means Trusted Facility Manual this
time [actually, it's a Guide, officially]). More work for the
overworked :-(