<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Files for login procedure in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250531#M90766</link>
    <description>1. In the beginning of login.com :&lt;BR /&gt;$ set watch file/class=all&lt;BR /&gt;--&amp;gt; very cryptic, all file accesses&lt;BR /&gt;&lt;BR /&gt;2. Image accouting&lt;BR /&gt;$ set acc/ena=image&lt;BR /&gt;--&amp;gt; all images executed, not all file used&lt;BR /&gt;&lt;BR /&gt;3. Audit&lt;BR /&gt;$ set audit/aud/enable=access=all&lt;BR /&gt;--&amp;gt; all file accesses of ALL processes, lots of lines and dangerous for performance. Good if directly disable after a few seconds.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
    <pubDate>Tue, 12 Aug 2008 11:53:14 GMT</pubDate>
    <dc:creator>Wim Van den Wyngaert</dc:creator>
    <dc:date>2008-08-12T11:53:14Z</dc:date>
    <item>
      <title>Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250530#M90765</link>
      <description>Can a log file be generated that will report what processes and system files are being processed as a user logs into a system? Does a log like this already exist?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Aug 2008 11:46:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250530#M90765</guid>
      <dc:creator>odwillia</dc:creator>
      <dc:date>2008-08-12T11:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250531#M90766</link>
      <description>1. In the beginning of login.com :&lt;BR /&gt;$ set watch file/class=all&lt;BR /&gt;--&amp;gt; very cryptic, all file accesses&lt;BR /&gt;&lt;BR /&gt;2. Image accouting&lt;BR /&gt;$ set acc/ena=image&lt;BR /&gt;--&amp;gt; all images executed, not all file used&lt;BR /&gt;&lt;BR /&gt;3. Audit&lt;BR /&gt;$ set audit/aud/enable=access=all&lt;BR /&gt;--&amp;gt; all file accesses of ALL processes, lots of lines and dangerous for performance. Good if directly disable after a few seconds.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Tue, 12 Aug 2008 11:53:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250531#M90766</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T11:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250532#M90767</link>
      <description>Forgot :&lt;BR /&gt;1. log is in sys$output&lt;BR /&gt;2. log via accouting/fu [acc filename]&lt;BR /&gt;3. log via anal/aud/fu [aud file name]&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Tue, 12 Aug 2008 11:55:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250532#M90767</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T11:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250533#M90768</link>
      <description>Have a look at the sylogin logical (usually points to sys$manager:sylogin.com) and the login file of the user (see with mc authorize sh user, the lgicmd).&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Aug 2008 12:45:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250533#M90768</guid>
      <dc:creator>labadie_1</dc:creator>
      <dc:date>2008-08-12T12:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250534#M90769</link>
      <description>Thanks for the reply.  In the beginning is it set "watch"?</description>
      <pubDate>Tue, 12 Aug 2008 12:45:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250534#M90769</guid>
      <dc:creator>odwillia</dc:creator>
      <dc:date>2008-08-12T12:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250535#M90770</link>
      <description>No logical for sylogin? Bad?&lt;BR /&gt;&lt;BR /&gt;$ sh log sylogin&lt;BR /&gt;%SHOW-S-NOTRAN, no translation for logical name SYLOGIN&lt;BR /&gt;$&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Aug 2008 12:47:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250535#M90770</guid>
      <dc:creator>odwillia</dc:creator>
      <dc:date>2008-08-12T12:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250536#M90771</link>
      <description>I would go for my 3. Then use anal/aud with /select=proc=id=xxx. The format will be easiest to read.&lt;BR /&gt; &lt;BR /&gt;But reset audit back to its original values asap after the test.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Tue, 12 Aug 2008 12:50:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250536#M90771</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T12:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250537#M90772</link>
      <description>The logical sys$login must be used to find the sylogin. The default is sys$manager:sylogin.com. That is for implementing 1. I would take 3.&lt;BR /&gt;&lt;BR /&gt;Post show audit/all if you don't know how to do it in detail.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Tue, 12 Aug 2008 13:07:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250537#M90772</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T13:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250538#M90773</link>
      <description>$ show audit/all&lt;BR /&gt;List of audit journals:&lt;BR /&gt;  Journal name:           SECURITY&lt;BR /&gt;  Journal owner:          (system audit journal)&lt;BR /&gt;  Destination:            SYS$COMMON:[SYSMGR]SECURITY.AUDIT$JOURNAL&lt;BR /&gt;  Monitoring:             enabled&lt;BR /&gt;    Warning thresholds,   Block count:    100     Duration:    2 00:00:00.0&lt;BR /&gt;    Action thresholds,    Block count:     25     Duration:    0 00:30:00.0&lt;BR /&gt;&lt;BR /&gt;Security auditing server characteristics:&lt;BR /&gt;  Database version:       4.4&lt;BR /&gt;  Backlog (total):        100, 200, 300&lt;BR /&gt;  Backlog (process):      5, 2&lt;BR /&gt;  Server processing intervals:&lt;BR /&gt;    Archive flush:        0 00:01:00.00&lt;BR /&gt;    Journal flush:        0 00:05:00.00&lt;BR /&gt;    Resource scan:        0 00:05:00.00&lt;BR /&gt;  Final resource action:  purge oldest audit events&lt;BR /&gt;&lt;BR /&gt;Security archiving information:&lt;BR /&gt;  Archiving events:       none&lt;BR /&gt;  Archive destination:&lt;BR /&gt;&lt;BR /&gt;System security alarms currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached,server&lt;BR /&gt;  Login:         batch,dialup&lt;BR /&gt;  Logfailure:    batch,dialup,local,remote,network,subprocess,detached&lt;BR /&gt;  Logout:        batch,dialup&lt;BR /&gt;&lt;BR /&gt;System security audits currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached,server&lt;BR /&gt;  Login:         batch,dialup&lt;BR /&gt;  Logfailure:    batch,dialup,local,remote,network,subprocess,detached&lt;BR /&gt;  Logout:        batch,dialup&lt;BR /&gt;$&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Aug 2008 13:37:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250538#M90773</guid>
      <dc:creator>odwillia</dc:creator>
      <dc:date>2008-08-12T13:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250539#M90774</link>
      <description>1) set aud/aud/ena=access=all&lt;BR /&gt;2) do your test (create the process)&lt;BR /&gt;3) set aud/aud/disa=access=all&lt;BR /&gt;4) wait 5 minutes to flush the audit buffers&lt;BR /&gt;5) anal/aud/fu/select=proc=id=xxx/out=x.lis -&lt;BR /&gt;SYS$COMMON:[SYSMGR]SECURITY.AUDIT$JOURNAL&lt;BR /&gt;&lt;BR /&gt;(untested !)&lt;BR /&gt;&lt;BR /&gt;xxx is the pid ofyour process. Alternative is /sel=proc=nam=yyy where yyy is the process name.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Tue, 12 Aug 2008 13:47:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250539#M90774</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T13:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250540#M90775</link>
      <description>In the mean time I tested it. Work. 1500 lines of output for 1 rlogin.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Tue, 12 Aug 2008 14:56:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250540#M90775</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T14:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250541#M90776</link>
      <description>Can I output this to a file?</description>
      <pubDate>Tue, 12 Aug 2008 16:41:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250541#M90776</guid>
      <dc:creator>odwillia</dc:creator>
      <dc:date>2008-08-12T16:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250542#M90777</link>
      <description>The output is in x.lis.&lt;BR /&gt;&lt;BR /&gt;But a $search x.lis file , object will be more clear to read.&lt;BR /&gt;&lt;BR /&gt;Wim@home</description>
      <pubDate>Tue, 12 Aug 2008 17:31:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250542#M90777</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-08-12T17:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Log Files for login procedure</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250543#M90778</link>
      <description>&amp;gt; No logical for sylogin? Bad?&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; $ sh log sylogin&lt;BR /&gt;&amp;gt; %SHOW-S-NOTRAN, no translation for logical name SYLOGIN&lt;BR /&gt;&lt;BR /&gt;The logical SYS$SYLOGIN points (normally) to SYS$MANAGER:SYLOGIN.COM which is the "common" login file.&lt;BR /&gt;&lt;BR /&gt;The logical SYS$LOGIN points to the user's "home" device:directory, where the user's default LOGIN.COM (normally) resides.&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Aug 2008 19:01:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/log-files-for-login-procedure/m-p/4250543#M90778</guid>
      <dc:creator>Doug Phillips</dc:creator>
      <dc:date>2008-08-12T19:01:48Z</dc:date>
    </item>
  </channel>
</rss>

