× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



I did the 5.3 instructions, and DO get IP addresses...

-----Original Message-----
From: security400-bounces@xxxxxxxxxxxx
[mailto:security400-bounces@xxxxxxxxxxxx] On Behalf Of ALopez@xxxxxxxxxx
Sent: Wednesday, May 02, 2007 12:45 PM
To: security400@xxxxxxxxxxxx
Subject: Re: [Security400] Finding IP address of Failed Login Attempt

If your system is at V5R4 you should use the new CPYAUDJRNE command
instead
of DSPAUDJRNE. Once the file has been created use your favorite query
to select and print the fields you are interested in. The IP address
from where the request originated should be in the header section of
each
*TYPE5
audit record.

Much like the screen capture, CPYAUDJRNE gives me a lot of blank fields,
but no IP address. Remote port shows 636, remote address is blank.
Device name, local name, network name, object name and library name are
all blank. The various reserved columns are blank.

If you are on an earlier release you should first use CRTDUPOBJ
OBJ(QASYPWJ5) FROMLIB(QSYS) OBJTYPE(*FILE) TOLIB(QTEMP) to create a
physical file in QTEMP and then use DSPJRN with OUTFILFMT(*TYPE5) to
copy
the PW audit records to that file. The remaining steps to display the
data
will be the same as for V5R4.

We are on V5R4, as current on CUMEs as one can get. I assume that
CPYAUDJRNE displays with *TYPE5--there doesn't seem to be an option to
control that.

For kicks, I followed the steps as though we were on a prior release,
and I can see plenty of IP addresses under other types of entries. PW
entries do not have this information.


As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.