Option for audit logging new sessions
Posted in 2013
User needed to log all successful new sessions (session ID, date/time, hostname, username) to an external file. Responses suggested using sysdbopen() and sysdbclose() procedures to query sysmaster:syssessions table, with a reference to an implementation example. User accepted this solution as adequate for their needs.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Security, Permissions & Auditing
We have a need to log all created sessions (successful logins only) to an external file (session id, date/time, hostname, username, etc). Is there an audit log configuration somewhere that we can use to do this? Thanks -Justin
Hello. The easiest way to implement it, locally on the server, is through sysdbopen, accessing sysmaster:syssessions table). But you have to implement that in all databases in the instance (or at least, all that you want to control). Regards. Alexandre Marini IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10 IBM Information Management Informix Technical Professional IBM Infosphere DataStage Technical Professional Informix Senior DBA - Orizon Brasil BRIUG website administrator Informix independent consultant > To: ids@iiug.org > From: jkillen@allamericanasphalt.com > Subject: Option for audit logging new sessions [31676] > Date: Wed, 9 Oct 2013 12:21:17 -0400 > > We have a need to log all created sessions (successful logins only) to an > external file (session id, date/time, hostname, username, etc). Is there an > audit log configuration somewhere that we can use to do this? > > Thanks > -Justin > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
I would use the sysdbopen() and the sysdbclose() procedures to do this work. Here is a link which describes something similar. http://informix.jfmiii.com/?p=122 John F. Miller III STSM, Lead Architect ids-bounces@iiug.org wrote on 10/09/2013 09:21:17 AM: > From: "Justin Killen" <jkillen@allamericanasphalt.com> > To: ids@iiug.org, > Date: 10/09/2013 09:22 AM > Subject: Option for audit logging new sessions [31676] > Sent by: ids-bounces@iiug.org > > We have a need to log all created sessions (successful logins only) to an > external file (session id, date/time, hostname, username, etc). Is there an > audit log configuration somewhere that we can use to do this? > > Thanks > -Justin > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
The subject of the message and great part of the body makes me think about the audit facility... But it really depends on "why" you need that? Currently audit facility will not be able to provide some of the required info: - session id (there is an RFE for this, and anybody can vote on it) - You don't mention it, but it currently does not provide session close. Session and database "close" are different things... although a session without a current database is AFAIK useles (but possible) - "etc" is vague. If you need to control the DBAs than sysdbopen()/sysdbclose() will not be able to provide that. Audit facility could provide you with role separation, which can assure you that even DBAs are captured... Again, it depends on the "why?", the real need for SID and the "etc". Regards On Wed, Oct 9, 2013 at 5:21 PM, Justin Killen < jkillen@allamericanasphalt.com> wrote: > We have a need to log all created sessions (successful logins only) to an > external file (session id, date/time, hostname, username, etc). Is there an > audit log configuration somewhere that we can use to do this? > > Thanks > -Justin > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a11c3eee42d6fce04e8553f17
Hi, You can create your own audit program by selecting from sysmaster:syssessions and dump it into a file. thanks
That's perfect John - thanks! -Justin -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of John Miller iii Sent: Wednesday, October 09, 2013 11:00 AM To: ids@iiug.org Subject: Re: Option for audit logging new sessions [31680] I would use the sysdbopen() and the sysdbclose() procedures to do this work. Here is a link which describes something similar. http://informix.jfmiii.com/?p=122 John F. Miller III STSM, Lead Architect ids-bounces@iiug.org wrote on 10/09/2013 09:21:17 AM: > From: "Justin Killen" <jkillen@allamericanasphalt.com> > To: ids@iiug.org, > Date: 10/09/2013 09:22 AM > Subject: Option for audit logging new sessions [31676] > Sent by: ids-bounces@iiug.org > > We have a need to log all created sessions (successful logins only) to an > external file (session id, date/time, hostname, username, etc). Is there an > audit log configuration somewhere that we can use to do this? > > Thanks > -Justin > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.