QUESTION POSED ON: 03 February 2008 I've been trying to monitor profiles with *ALLOBJ or above authority using QHST, because QSECOFR has the authority to delete audit logs. Are there any queries or easy methods to audit *ALLOBJ or above profiles besides manually going into QHST daily and searching the spooled report to find users who I know have *ALLOBJ access? This method is not showing accurate information consistently.
>
EXPERT RESPONSE
QHST is not a reliable source. It can be deleted or cleared. The only reliable source of this type of information is the i5/OS audit journal. While entire receivers can be deleted, individual entries cannot. Even if QSECOFR was to delete an entire receiver, they are in sequence so you could tell if a receiver was missing and go look for the corresponding audit journal entry that documents the deletion.
Search and Browse the Expert Answer Center Search and browse more than 25,000 question and
answer pairs from more than 250 TechTarget industry experts.
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.