<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Advanced Server V7.3A audit log files in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811335#M52442</link>
    <description>Hi Leo,&lt;BR /&gt;&lt;BR /&gt;You need to also enable audit monitoring on the directories and files in question by using;&lt;BR /&gt;&lt;BR /&gt;ADMIN SET FILE \dir\foo.bar AUDIT=(SUCCESS=ALL, FAILURE=ALL)&lt;BR /&gt;&lt;BR /&gt;For more information, see section 2.2.2 &amp;amp; 6.1.3.6 in the AS admin guide, link below;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/73final/6556/6556pro.pdf" target="_blank"&gt;http://h71000.www7.hp.com/doc/73final/6556/6556pro.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;BR /&gt;John.</description>
    <pubDate>Sat, 24 Jun 2006 07:20:50 GMT</pubDate>
    <dc:creator>John Abbott_2</dc:creator>
    <dc:date>2006-06-24T07:20:50Z</dc:date>
    <item>
      <title>Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811331#M52438</link>
      <description>Hello All,&lt;BR /&gt;&lt;BR /&gt;Since our PC user community is transferring form Windows NT to Windows XP and in the course of this transfer having their domains and usernames changed (we systems managers have to keep ourselves busy), the access to some Advanced server shares fails.&lt;BR /&gt;Now I have changed the permission for the user but he still cannot gain access. I have given myself full control and can access the share.&lt;BR /&gt;In order to do trouble shooting, I have enabled auditing (set audit policy /success=access /failure=access), done some successful and not successful access, but&lt;BR /&gt;show events /type=security /server=... gives "Security event log has no records".&lt;BR /&gt;&lt;BR /&gt;Am I looking in the right place for the audit logs? Have I enabled the right audit trail?&lt;BR /&gt;&lt;BR /&gt;With kind regards,&lt;BR /&gt;Leo de Lange</description>
      <pubDate>Fri, 23 Jun 2006 07:55:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811331#M52438</guid>
      <dc:creator>L.P. de Lange</dc:creator>
      <dc:date>2006-06-23T07:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811332#M52439</link>
      <description>Hi Leo, firstly welcome to the OpenVMS forum!&lt;BR /&gt;&lt;BR /&gt;&amp;gt; domains and usernames changed &lt;BR /&gt;&lt;BR /&gt;Are the WNT and WXP in different domains ? What about AS, another domain ? Have you a trust relationship set-up between these domains ? (ADMIN SHOW TRUST)&lt;BR /&gt;&lt;BR /&gt;What AS 7.3 ECO kit are you running ? ($ PROD SHO PROD)&lt;BR /&gt;&lt;BR /&gt;Do you get any events at all ? e.g. AMIN SHOW EVENT/SINCE=start_of_pathworks&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;BR /&gt;John.</description>
      <pubDate>Fri, 23 Jun 2006 08:17:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811332#M52439</guid>
      <dc:creator>John Abbott_2</dc:creator>
      <dc:date>2006-06-23T08:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811333#M52440</link>
      <description>Leo,&lt;BR /&gt;&lt;BR /&gt;did you also set a spec. file or directory for auditing (set file /audit)?&lt;BR /&gt;&lt;BR /&gt;What version are you using (actual is V7.3A-Eco4)? &lt;BR /&gt;&lt;BR /&gt;Are some shares working or are only spec. shares/users encounter problems?&lt;BR /&gt;&lt;BR /&gt;regards Kalle</description>
      <pubDate>Fri, 23 Jun 2006 08:18:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811333#M52440</guid>
      <dc:creator>Karl Rohwedder</dc:creator>
      <dc:date>2006-06-23T08:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811334#M52441</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Thanks for all the quick replies and I will try to give you some answers, marked with LL:&lt;BR /&gt;&lt;BR /&gt;Are the WNT and WXP in different domains ? What about AS, another domain ? Have you a trust relationship set-up between these domains ?&lt;BR /&gt;LL: WNT and WXP are in different domains. However, I changed the permission to the new domain and username.&lt;BR /&gt;&lt;BR /&gt;What version are you using (actual is V7.3A-Eco4)?&lt;BR /&gt;LL: We are running this version.&lt;BR /&gt;&lt;BR /&gt;Are some shares working or are only spec. shares/users encounter problems?&lt;BR /&gt;LL: I have given myself (with my WXP username) permission for this specific share and can access it. So the user is entountering problems.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Do you get any events at all ?&lt;BR /&gt;LL: Yes, I do see some events, the last from june 6th. (system events that is)&lt;BR /&gt;&lt;BR /&gt;With kind regards,&lt;BR /&gt;Leo de Lange&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Jun 2006 08:27:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811334#M52441</guid>
      <dc:creator>L.P. de Lange</dc:creator>
      <dc:date>2006-06-23T08:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811335#M52442</link>
      <description>Hi Leo,&lt;BR /&gt;&lt;BR /&gt;You need to also enable audit monitoring on the directories and files in question by using;&lt;BR /&gt;&lt;BR /&gt;ADMIN SET FILE \dir\foo.bar AUDIT=(SUCCESS=ALL, FAILURE=ALL)&lt;BR /&gt;&lt;BR /&gt;For more information, see section 2.2.2 &amp;amp; 6.1.3.6 in the AS admin guide, link below;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/73final/6556/6556pro.pdf" target="_blank"&gt;http://h71000.www7.hp.com/doc/73final/6556/6556pro.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;BR /&gt;John.</description>
      <pubDate>Sat, 24 Jun 2006 07:20:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811335#M52442</guid>
      <dc:creator>John Abbott_2</dc:creator>
      <dc:date>2006-06-24T07:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811336#M52443</link>
      <description>Hi Leo,&lt;BR /&gt;&lt;BR /&gt;This one always gets folks - you need to _enable_ auditing as well.  If you do $ ADMIN SHOW AUDIT POLICY the 2nd line output will indicate if auditing is enabled or disabled.  &lt;BR /&gt;&lt;BR /&gt;You simply forgot the /ENABLE qualifier when you did the ADMIN SET AUDIT POLICY ... command; so now just do:&lt;BR /&gt;&lt;BR /&gt;$ ADMIN SET AUDIT POLICY/ENABLE&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Paul</description>
      <pubDate>Sat, 24 Jun 2006 07:20:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811336#M52443</guid>
      <dc:creator>Paul Nunez</dc:creator>
      <dc:date>2006-06-24T07:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811337#M52444</link>
      <description>Hello All,&lt;BR /&gt;&lt;BR /&gt;I did have to give the command&lt;BR /&gt;   set file "sharename" "username" /audit=...&lt;BR /&gt;to enable auditing, but have come no further. To give you the current status, I have included some commands and their output:&lt;BR /&gt;&lt;BR /&gt;\\DHCLX3\\DHAX25&amp;gt; show file CKMKA122 /audit&lt;BR /&gt;&lt;BR /&gt;Files in: \\DHAX25\CKMKA122&lt;BR /&gt;&lt;BR /&gt;  .            &lt;DIR&gt;&lt;BR /&gt;    Audit Events:                        Success    Failure&lt;BR /&gt;      MOD\u00b816                        RWXDPO     RWXDPO&lt;BR /&gt;      MOD\u00l0p8                        RWXDPO     RWXDPO&lt;BR /&gt;&lt;BR /&gt;  Total of 1 file&lt;BR /&gt;                                                           &lt;BR /&gt;&lt;BR /&gt;\\DHCLX3\\DHAX25&amp;gt; show audit policy&lt;BR /&gt;&lt;BR /&gt;Audit Policy for domain "\\DHCLX3":&lt;BR /&gt;&lt;BR /&gt;Auditing is currently Enabled.&lt;BR /&gt;&lt;BR /&gt;Audit Event states:&lt;BR /&gt;&lt;BR /&gt;Audit Event         Success   Failure&lt;BR /&gt;------------------  --------  --------&lt;BR /&gt;ACCESS              Enabled   Enabled&lt;BR /&gt;ACCOUNT_MANAGEMENT  Disabled  Disabled&lt;BR /&gt;LOGONOFF            Disabled  Disabled&lt;BR /&gt;POLICY_CHANGE       Disabled  Disabled&lt;BR /&gt;PROCESS             Disabled  Disabled&lt;BR /&gt;SYSTEM              Disabled  Disabled&lt;BR /&gt;USER_RIGHTS         Disabled  Disabled&lt;BR /&gt;&lt;BR /&gt;\\DHCLX3\\DHAX25&amp;gt; show events /type=security&lt;BR /&gt;%PWRK-I-EVTNOREC, Security Event Log on server "DHAX25" has no records&lt;BR /&gt;&lt;BR /&gt;\\DHCLX3\\DHAX25&amp;gt; show events /type=security  /server=dhax22&lt;BR /&gt;%PWRK-I-EVTNOREC, Security Event Log on server "DHAX22" has no records&lt;BR /&gt;&lt;BR /&gt;---------------------&lt;BR /&gt;dhclx3 is our cluster alias, dhax22 &amp;amp; dhax25 the nodes. ckmka122 the sharename, mod\u00l0p8 is my account.&lt;BR /&gt;I have accessed the share, before giving the show events commands.&lt;BR /&gt;&lt;BR /&gt;With kind regards,&lt;BR /&gt;Leo de Lange&lt;/DIR&gt;</description>
      <pubDate>Mon, 26 Jun 2006 02:36:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811337#M52444</guid>
      <dc:creator>L.P. de Lange</dc:creator>
      <dc:date>2006-06-26T02:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811338#M52445</link>
      <description>Hi, &lt;BR /&gt;does your Advanced server configured as PDC? If not, try to find security log on PDC in this domain.&lt;BR /&gt;Petr</description>
      <pubDate>Mon, 26 Jun 2006 05:27:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811338#M52445</guid>
      <dc:creator>Petr Spisek</dc:creator>
      <dc:date>2006-06-26T05:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced Server V7.3A audit log files</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811339#M52446</link>
      <description>Hi Leo, tested this out here, without any problems using... from AS admin&lt;BR /&gt;&lt;BR /&gt;set file path\file everyone  /AUDIT=(SUC=ALL,FAIL=ALL)&lt;BR /&gt;&lt;BR /&gt;accessed and updated the 'file' from my PC (PC on another domaim, with a trust relationship)&lt;BR /&gt;&lt;BR /&gt;show event/full/since=nn:nn/type=sec&lt;BR /&gt;&lt;BR /&gt;I can see in the security event log for the AS domain the event for the file I updated from my PC, it shows the trusted domain, my username, file updated etc.&lt;BR /&gt;&lt;BR /&gt;Can you change/view the audit setting from the file | properties | security | advanced | audit pain from windows file explorer ? do they look right ?&lt;BR /&gt;&lt;BR /&gt;Are you accessing the right event log.. Have you tied the 'eventvwr' from windows ? Right Click on Event viewer (local) and click on 'connect to another computer' - enter the PDC of the pathworks as domain.&lt;BR /&gt;&lt;BR /&gt;J.&lt;BR /&gt;PS. My PDC is a Windows box.&lt;BR /&gt;</description>
      <pubDate>Mon, 26 Jun 2006 05:52:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/advanced-server-v7-3a-audit-log-files/m-p/3811339#M52446</guid>
      <dc:creator>John Abbott_2</dc:creator>
      <dc:date>2006-06-26T05:52:50Z</dc:date>
    </item>
  </channel>
</rss>

