<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Analysing Audit in VMS server in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032312#M83667</link>
    <description>... meaning the system was NOT ...&lt;BR /&gt;Missed 1 word.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
    <pubDate>Wed, 07 Mar 2007 07:06:46 GMT</pubDate>
    <dc:creator>Wim Van den Wyngaert</dc:creator>
    <dc:date>2007-03-07T07:06:46Z</dc:date>
    <item>
      <title>Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032305#M83660</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;When I am trying to analyse the audit journal log, it is only showing me the information after the crash time i.e. the server crashed at 13:57 hrs yesterday. I want information before crash also. I am using &lt;BR /&gt;&lt;BR /&gt;ANA/AUDIT/SINCE=01-MAR-2007 ......&lt;BR /&gt;&lt;BR /&gt;Can anybody help me in this please?</description>
      <pubDate>Wed, 07 Mar 2007 04:45:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032305#M83660</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2007-03-07T04:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032306#M83661</link>
      <description>you must add the name of the previous audit server file &lt;BR /&gt;&lt;BR /&gt;$ ana/audit/since=... sys$common:[sysmgr]SECURITY.AUDIT$JOURNAL;-1&lt;BR /&gt;&lt;BR /&gt;or another location if you use the logical name for audit.</description>
      <pubDate>Wed, 07 Mar 2007 04:49:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032306#M83661</guid>
      <dc:creator>labadie_1</dc:creator>
      <dc:date>2007-03-07T04:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032307#M83662</link>
      <description>There are no more journal file &amp;amp; this is the only file which system has dated back year 1994.</description>
      <pubDate>Wed, 07 Mar 2007 05:00:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032307#M83662</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2007-03-07T05:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032308#M83663</link>
      <description>Noorul...you should have a version prior to the crash...after the crash a new version would be created.&lt;BR /&gt;&lt;BR /&gt;I am not sure if the audit files are being moved to a different location. I would suggest that you search &lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;Mobeen</description>
      <pubDate>Wed, 07 Mar 2007 05:02:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032308#M83663</guid>
      <dc:creator>Mobeen_1</dc:creator>
      <dc:date>2007-03-07T05:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032309#M83664</link>
      <description>When audit restarts after a crash, no new file is created. You should be able to read the info from before the crash. But remind this : audit_server writes info defered. Thus some info is lost when you have a crash&lt;BR /&gt;&lt;BR /&gt;Check "journal flush" in show aud/all. I have it at 15 seconds.&lt;BR /&gt;&lt;BR /&gt;If this is not it, post show audit/all.&lt;BR /&gt;&lt;BR /&gt;Wim&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Mar 2007 05:33:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032309#M83664</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-07T05:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032310#M83665</link>
      <description>Hi Wim,&lt;BR /&gt;Journal Flush is showing 0 00:05:00.00 to me</description>
      <pubDate>Wed, 07 Mar 2007 05:38:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032310#M83665</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2007-03-07T05:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032311#M83666</link>
      <description>Just "crashed" my station and :&lt;BR /&gt;&lt;BR /&gt;I do get previous records in audit ...&lt;BR /&gt;&lt;BR /&gt;Try removing the /sin to see if there are record from before 1-mar (meaning the system was doing any audit violations between 1-mar and the crash).&lt;BR /&gt;&lt;BR /&gt;I hope you did do show audit/all to find the name of the file to use in anal/aud. Very often an (old) file is present in the default location (your current directory). But of course, if you see the events from after the crash this could not be the case.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 07 Mar 2007 05:59:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032311#M83666</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-07T05:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032312#M83667</link>
      <description>... meaning the system was NOT ...&lt;BR /&gt;Missed 1 word.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 07 Mar 2007 07:06:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032312#M83667</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-07T07:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032313#M83668</link>
      <description>Wim,&lt;BR /&gt;&lt;BR /&gt;Yes I tried for Ana/Audit and it is displaying all the information since 1996 excluding the part just before the crash in which I am interested.</description>
      <pubDate>Wed, 07 Mar 2007 07:30:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032313#M83668</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2007-03-07T07:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032314#M83669</link>
      <description>So, there was no audit event (violation)between 1-mar and 5 minutes before the crash (your setting).&lt;BR /&gt;&lt;BR /&gt;Sure you need audit and not accounting (which also uses defered write and thus you may be missing some stuff too).&lt;BR /&gt;&lt;BR /&gt;Wim&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Mar 2007 07:39:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032314#M83669</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-07T07:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032315#M83670</link>
      <description>Hassan,&lt;BR /&gt;&lt;BR /&gt;hi, &lt;BR /&gt;&lt;BR /&gt;you can check in SDA&amp;gt; for crash information.&lt;BR /&gt;&lt;BR /&gt;Atul Sardana</description>
      <pubDate>Wed, 07 Mar 2007 22:21:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032315#M83670</guid>
      <dc:creator>atul sardana</dc:creator>
      <dc:date>2007-03-07T22:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032316#M83671</link>
      <description>Hassan,&lt;BR /&gt;&lt;BR /&gt;hi, &lt;BR /&gt;&lt;BR /&gt;you can check in SDA&amp;gt; for crash information.&lt;BR /&gt;and error log also&lt;BR /&gt;&lt;BR /&gt;Atul Sardana</description>
      <pubDate>Wed, 07 Mar 2007 22:22:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032316#M83671</guid>
      <dc:creator>atul sardana</dc:creator>
      <dc:date>2007-03-07T22:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032317#M83672</link>
      <description>Is it possible that audit_server was not writing events just prior to the crash because of the problem that caused the crash?. What was the bugcheck? and in what state was the audit_server process?.</description>
      <pubDate>Thu, 08 Mar 2007 04:51:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032317#M83672</guid>
      <dc:creator>Martin Hughes</dc:creator>
      <dc:date>2007-03-08T04:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032318#M83673</link>
      <description>Unless the system was sitting idle, or you were auditing only a very few things, it seems unlikely to me that you would have no audited events during the last 6 days.&lt;BR /&gt;&lt;BR /&gt;Did a disk fill up?&lt;BR /&gt;&lt;BR /&gt;Can you tell us anything about the crash?&lt;BR /&gt;&lt;BR /&gt;Did you get a valid crash dump file?  If so it has a higher chance of providing some useful information.&lt;BR /&gt;&lt;BR /&gt;Are you sure auditing was not disabled before the crash?  Was there a logical name redirecting the audit journal file to a non-standard location?&lt;BR /&gt;&lt;BR /&gt;What events were you expecting to be audited, i.e. what does the output of "show audit" show?  You stated that there are new audit records since the system was rebooted; have you determined when the previous audit record before the crash was written?  If it was from before the previous boot, then auditing was either disabled, or being written to a different journal file.&lt;BR /&gt;&lt;BR /&gt;If the crash was not maliciously induced, then there will probably be useful information in the crash dump file.</description>
      <pubDate>Thu, 08 Mar 2007 07:15:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032318#M83673</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2007-03-08T07:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032319#M83674</link>
      <description>Crash dump shows that the server crashed due to UCX problem. Audit was enabled beore crash.&lt;BR /&gt;&lt;BR /&gt;On the time of crash some body (planned test) has very frequently tried to ping/telnet the server, which resulted the server to crash. The servers which did not crash becuase of this ping/telnet, reveals this  in the audit file. I want to know, Is the server crashed due to excessive UCX packets received.</description>
      <pubDate>Thu, 08 Mar 2007 07:56:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032319#M83674</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2007-03-08T07:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032320#M83675</link>
      <description>If you want to know why the server crashed, you need to examine the system dump file...&lt;BR /&gt;&lt;BR /&gt;PINGs will not be logged in AUDIT server.&lt;BR /&gt;&lt;BR /&gt;Whether TELNET login attempts will be audited, depends on your audit settings.&lt;BR /&gt;&lt;BR /&gt;You could also check for TELNET login failures using ACCOUNTING, if that was enabled at the time of the problem.&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Sat, 10 Mar 2007 03:21:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032320#M83675</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2007-03-10T03:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032321#M83676</link>
      <description>Hi Hassan,&lt;BR /&gt;&lt;BR /&gt;if you want to know who.....&lt;BR /&gt;you can check which ip continuous tried before crash on server in operator.log file in sys$manager.&lt;BR /&gt;&lt;BR /&gt;Thanks ,&lt;BR /&gt;&lt;BR /&gt;Atul Sardana&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 10 Mar 2007 03:46:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032321#M83676</guid>
      <dc:creator>atul sardana</dc:creator>
      <dc:date>2007-03-10T03:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032322#M83677</link>
      <description>&lt;QUOTE&gt;&lt;BR /&gt;you can check which ip continuous tried before crash on server in operator.log file in sys$manager.&lt;BR /&gt;&lt;/QUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;If the system ahd time to write to the OPERATOR.LOG file before the crash. otherwise you could still try to find those OPCOM messages in the system dump (in P0 space of the OPCOM process).&lt;BR /&gt;&lt;BR /&gt;And this will depend on whether your IP service is set up to log events to OPCOM...&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Sat, 10 Mar 2007 03:50:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032322#M83677</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2007-03-10T03:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Analysing Audit in VMS server</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032323#M83678</link>
      <description>Thanks all, the issue is resolved.</description>
      <pubDate>Mon, 14 May 2007 09:34:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/analysing-audit-in-vms-server/m-p/5032323#M83678</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2007-05-14T09:34:55Z</dc:date>
    </item>
  </channel>
</rss>

