Home > AS/400 Tips > iSeries security tips > Making sense of the security audit journals
iSeries 400 Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ISERIES SECURITY TIPS

Making sense of the security audit journals


Rich Loeber
03.06.2007
Rating: -4.29- (out of 5)


iSeries news and advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Rich Loeber
To track security events on your System i, IBM has quite nicely provided an extensive security audit journal function to help you. When you have security auditing active on your system, all sorts of relevant security information is regularly stored in your system security audit journal that will help you to know what's going on with your system. This is a great feature for the System i OS, but capturing the audit information and then using it in a meaningful way are two different things.

More Information

This tip will just scratch the surface of how you can start to make some sense out of all the information that is stored with your system security audit journal.

The secret that starts the process of unlocking the system audit journal is the Display Journal (DSPJRN) command. To work with the system audit journal, run this command for the journal named QAUDJRN.

The command defaults to displaying information to your terminal screen. This is a hard way to wade through the information, although there are any number of filters that you can use to limit the information displayed.

A better way to work with this information is to run the Display Journal command using one of the options that transfers the journal information into a normalized database file. This is done by selecting the option OUTPUT(*OUTFILE). When you do this, you will have to specify the format for the output file. There are five different formats offered, from *TYPE1 through *TYPE5. You can use the HELP function to see the difference. Each higher number format builds on the information in the base *TYPE1 format. If you're just starting, the *TYPE1 format should be sufficient.

Once you have your database built, then it is time to start analyzing it to see just what you have recorded in your security audit journal. For starters, I recommend that you run summary reports on fields like the Entry Type, Job Name, User Profile and so on to see how many records you have in your current journal with various values. On our test system here, I do this with the old "Query Two Step" of summarizing the information to a file and then reporting that file. I have some Query/400 definitions that I've created for this purpose that I would be happy to share with you in a save file that you can restore to your system. If you'd like a copy, just let me know and I'll send them to you.

As you work with the databases that you've created and the various analysis reports that you work with, you will also need to have a copy of the iSeries Security Manual handy. There are at least 100 pages in the Appendix (on ours, it is Appendix F) that describe all of the information in the various database formats, not to mention the codes that can be contained and what they mean. On our system, I've even found codes in the security audit journal that are not documented in the Security Manual. In that case, the next stop is IBM support.

If the tasks seems too daunting for you, I'm certain that you will not be the first security officer who has thrown in the towel on analyzing this audit journal. There are a number of third party software solutions that have taken the time to do all of the necessary investigation and one of them might just fill the bill for you, not to mention lowering your blood pressure.

---------------------------
About the author: Rich Loeber is president of Kisco Information Systems Inc. in Saranac Lake, N.Y. The company is a provider of various security products for the iSeries market.


Rate this Tip
To rate tips, you must be a member of Search400.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
iSeries security tips
A guide to System i security, Part 3: Digging in to the System i security environment
Is your AS/400 secure?: How a hacker could get valuable information from your system
System i security report round-up
A guide to System i security, part 2: Landing and establishing access
Creating a System i database security policy: Implementation
A guide to System i security: Descending into the heart of darkness of IT security
Creating a System i database security policy: First steps
Enhancements in the intrusion detection system for i5/OS V6R1
Six common System i security lapses
Working with exit programs in i5/OS V6

iSeries system and application security
A guide to System i security, Part 3: Digging in to the System i security environment
Primary group authority: How it works
Blocking access to SQL line commands
Moving files to new libraries allows access to only groups or users that are authorized
Changing telnet ports: A security solution?
Moving to security level 30
Menu security's relationship to object authority
Encrypting files or fields on the iSeries
Changing the QSECOFR password
Ensuring security on i runbook

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
midrange  (Search400.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 1999 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts