|
I did the 5.3 instructions, and DO get IP addresses...
-----Original Message-----
From: security400-bounces@xxxxxxxxxxxx
[mailto:security400-bounces@xxxxxxxxxxxx] On Behalf Of ALopez@xxxxxxxxxx
Sent: Wednesday, May 02, 2007 12:45 PM
To: security400@xxxxxxxxxxxx
Subject: Re: [Security400] Finding IP address of Failed Login Attempt
If your system is at V5R4 you should use the new CPYAUDJRNE commandinstead
of DSPAUDJRNE. Once the file has been created use your favorite query*TYPE5
to select and print the fields you are interested in. The IP address
from where the request originated should be in the header section of
each
audit record.
Much like the screen capture, CPYAUDJRNE gives me a lot of blank fields,
but no IP address. Remote port shows 636, remote address is blank.
Device name, local name, network name, object name and library name are
all blank. The various reserved columns are blank.
If you are on an earlier release you should first use CRTDUPOBJcopy
OBJ(QASYPWJ5) FROMLIB(QSYS) OBJTYPE(*FILE) TOLIB(QTEMP) to create a
physical file in QTEMP and then use DSPJRN with OUTFILFMT(*TYPE5) to
the PW audit records to that file. The remaining steps to display thedata
will be the same as for V5R4.
We are on V5R4, as current on CUMEs as one can get. I assume that
CPYAUDJRNE displays with *TYPE5--there doesn't seem to be an option to
control that.
For kicks, I followed the steps as though we were on a prior release,
and I can see plenty of IP addresses under other types of entries. PW
entries do not have this information.
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400)
mailing list To post a message email: Security400@xxxxxxxxxxxx To
subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request@xxxxxxxxxxxx Before posting, please take a
moment to review the archives at
http://archive.midrange.com/security400.
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.