<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271478#M92227</link>
    <description>Please look at sys$manager:sylogicals.template.&lt;BR /&gt;&lt;BR /&gt;This has a list of the "Site-specific VMScluster core file definitions" that should be the same for all memebers of the cluster.&lt;BR /&gt;&lt;BR /&gt;The intent is that VMS$AUDIT_SERVER be one file that is shared by all cluster nodes.&lt;BR /&gt;&lt;BR /&gt;Where are you defining VMS$AUDIT_SERVER?  It needs to be defined before the audit server starts.  SYS$MANAGER:SYLOGICALS.COM is the normal place where it would be defined.&lt;BR /&gt;&lt;BR /&gt;I am attaching an extract from sys$manager:sylogicals.com on an Alpha VMS 8.3 system.&lt;BR /&gt;&lt;BR /&gt;Jon&lt;BR /&gt;</description>
    <pubDate>Wed, 17 Sep 2008 23:25:00 GMT</pubDate>
    <dc:creator>Jon Pinkley</dc:creator>
    <dc:date>2008-09-17T23:25:00Z</dc:date>
    <item>
      <title>%SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271475#M92224</link>
      <description>After getting this message at the end of the SHOW AUDIT display (shown below) we have come to conclusion that the file VMS$AUDIT_SERVER.DAT can be located in different locations using the logical, VMS$AUDIT_SERVER, but that doesn't mean that it can be shared by a cluster.  That is, every node must have it's own VMS$AUDIT_SERVER.DAT.  We have our logical pointing to the same spot on both nodes and the audit server only runs and collects data on the first node to start.  Does anyone agree with this or have a different idea of what our audit server problem might be?&lt;BR /&gt;&lt;BR /&gt;$ show audit&lt;BR /&gt;System security alarms currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached&lt;BR /&gt;  Logfailure:    batch,dialup,local,subprocess,detached&lt;BR /&gt;&lt;BR /&gt;System security audits currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  SYSGEN&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached&lt;BR /&gt;  Logfailure:    batch,dialup,local,remote,network,subprocess,detached&lt;BR /&gt;  Privilege use:&lt;BR /&gt;    OPER&lt;BR /&gt;&lt;BR /&gt;%SHOW-W-NOAUDITING, security auditing disabled; no events will be logged&lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;Clark Powell&lt;BR /&gt;</description>
      <pubDate>Wed, 17 Sep 2008 21:11:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271475#M92224</guid>
      <dc:creator>Clark Powell</dc:creator>
      <dc:date>2008-09-17T21:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271476#M92225</link>
      <description>what does show audit/all say at the top?</description>
      <pubDate>Wed, 17 Sep 2008 22:39:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271476#M92225</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-17T22:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271477#M92226</link>
      <description>As far as VMS$AUDIT_SERVER.DAT, we have a 2 node cluster running Alpha VMS 7.3-2 from a common system disk.  We do not have VMS$AUDIT_SERVER defined as a logical name.&lt;BR /&gt;&lt;BR /&gt;The file is in our sys$common:[sysmgr] directory, and it is shared by both nodes.&lt;BR /&gt;&lt;BR /&gt;This is a realatively small file, it has the audit settings in it, not the audit records.&lt;BR /&gt;&lt;BR /&gt;What version(s) of VMS are in your cluster?&lt;BR /&gt;&lt;BR /&gt;I am not sure, but I think this information needs to be the same on all cluster nodes, i.e. I don't believe it is possible to have different items audited on different nodes, although I have never tried puting the VMS$AUDIT_SERVER.DAT file in a system specific location.&lt;BR /&gt;&lt;BR /&gt;Jon</description>
      <pubDate>Wed, 17 Sep 2008 22:56:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271477#M92226</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-17T22:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271478#M92227</link>
      <description>Please look at sys$manager:sylogicals.template.&lt;BR /&gt;&lt;BR /&gt;This has a list of the "Site-specific VMScluster core file definitions" that should be the same for all memebers of the cluster.&lt;BR /&gt;&lt;BR /&gt;The intent is that VMS$AUDIT_SERVER be one file that is shared by all cluster nodes.&lt;BR /&gt;&lt;BR /&gt;Where are you defining VMS$AUDIT_SERVER?  It needs to be defined before the audit server starts.  SYS$MANAGER:SYLOGICALS.COM is the normal place where it would be defined.&lt;BR /&gt;&lt;BR /&gt;I am attaching an extract from sys$manager:sylogicals.com on an Alpha VMS 8.3 system.&lt;BR /&gt;&lt;BR /&gt;Jon&lt;BR /&gt;</description>
      <pubDate>Wed, 17 Sep 2008 23:25:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271478#M92227</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-17T23:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271479#M92228</link>
      <description>Perhaps someone defined SYS$AUDIT_SERVER_INHIBIT? Check with SHOW LOGICAL.&lt;BR /&gt;&lt;BR /&gt;regards Kalle</description>
      <pubDate>Thu, 18 Sep 2008 03:54:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271479#M92228</guid>
      <dc:creator>Karl Rohwedder</dc:creator>
      <dc:date>2008-09-18T03:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271480#M92229</link>
      <description>We have a cluster with 2 system disks and 1 shared SAN disk with the common data. We did set aud/dest= to define a common audit file. No problem yet after 6 years.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 18 Sep 2008 06:28:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271480#M92229</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-09-18T06:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271481#M92230</link>
      <description>BTW : our vms$audit_server.dat is on each system disk. It's our responsibility to keep the setting on both nodes the same.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 18 Sep 2008 06:43:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271481#M92230</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-09-18T06:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271482#M92231</link>
      <description>Just tried to use a common file in a test. No problem at all (7.3).&lt;BR /&gt;1) did you define the logical on both nodes&lt;BR /&gt;2) did you restart audit_server on both nodes&lt;BR /&gt;3) is the destination as shown in show aud/all seen by both nodes &amp;gt; &lt;BR /&gt;4) nothing in the operator log file/accounting ?&lt;BR /&gt;&lt;BR /&gt;Wim&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 18 Sep 2008 08:11:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271482#M92231</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-09-18T08:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271483#M92232</link>
      <description>MORE BACKGROUND:&lt;BR /&gt;   I have been so uniform in screwing up the audit server on both our Cert and Prod clusters that they have exactly same problem.  In each cluster (alpha 8.3 almost all patches) there are two nodes, two separate system disk, logical VMS$AUDIT_SERVER defined on both nodes, logical SYS$AUDIT_SERVER_INHIBIT not defined, (see below,) At boot audit server does not start on both nodes.  Here on our Cert cluster you can see what it looks like&lt;BR /&gt;right after boot with ALPHAX not running the audit server:&lt;BR /&gt;SYSMAN&amp;gt; DO SHO AUDIT&lt;BR /&gt;%SYSMAN-I-OUTPUT, command execution on node ALPHAZ&lt;BR /&gt;System security alarms currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached&lt;BR /&gt;System security audits currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  SYSGEN&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached&lt;BR /&gt;  Logfailure:    batch,dialup,local,remote,network,subprocess,detached&lt;BR /&gt;  Privilege use:&lt;BR /&gt;    OPER&lt;BR /&gt;%SYSMAN-I-OUTPUT, command execution on node ALPHAX&lt;BR /&gt;System security alarms currently disabled&lt;BR /&gt;System security audits currently disabled&lt;BR /&gt;%SHOW-W-NOAUDSRV, AUDIT_SERVER process not running; use "SET AUDIT/SERVER=START"&lt;BR /&gt; to start&lt;BR /&gt;%SHOW-W-NOAUDITING, security auditing disabled; no events will be logged&lt;BR /&gt;&lt;BR /&gt;But after executing the SET AUDIT/SERVER=START we get what you see below.&lt;BR /&gt;&lt;BR /&gt;To answer the second respondent on production cluster.  I checked this command on both nodes and except for the SHOW-W-NOAUDITING error message the output is the same.&lt;BR /&gt;&lt;BR /&gt;ALPHAC&amp;gt; sho audit/all&lt;BR /&gt;List of audit journals:&lt;BR /&gt;  Journal name:           SECURITY&lt;BR /&gt;  Journal owner:          (system audit journal)&lt;BR /&gt;  Destination:            SYS$COMMON:[SYSMGR]SECURITY.AUDIT$JOURNAL&lt;BR /&gt;  Monitoring:             enabled&lt;BR /&gt;    Warning thresholds,   Block count:    100     Duration:    2 00:00:00.0&lt;BR /&gt;    Action thresholds,    Block count:     25     Duration:    0 00:30:00.0&lt;BR /&gt;&lt;BR /&gt;Security auditing server characteristics:&lt;BR /&gt;  Database version:       4.4&lt;BR /&gt;  Backlog (total):        100, 200, 700&lt;BR /&gt;  Backlog (process):      5, 2&lt;BR /&gt;  Server processing intervals:&lt;BR /&gt;    Archive flush:        0 00:01:00.00&lt;BR /&gt;    Journal flush:        0 00:05:00.00&lt;BR /&gt;    Resource scan:        0 00:05:00.00&lt;BR /&gt;  Final resource action:  purge oldest audit events&lt;BR /&gt;&lt;BR /&gt;Security archiving information:&lt;BR /&gt;  Archiving events:       none&lt;BR /&gt;  Archive destination:&lt;BR /&gt;&lt;BR /&gt;System security alarms currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached&lt;BR /&gt;  Logfailure:    batch,dialup,local,subprocess,detached&lt;BR /&gt;&lt;BR /&gt;System security audits currently enabled for:&lt;BR /&gt;  ACL&lt;BR /&gt;  Authorization&lt;BR /&gt;  SYSGEN&lt;BR /&gt;  Audit:         illformed&lt;BR /&gt;  Breakin:       dialup,local,remote,network,detached&lt;BR /&gt;  Logfailure:    batch,dialup,local,remote,network,subprocess,detached&lt;BR /&gt;  Privilege use:&lt;BR /&gt;    OPER&lt;BR /&gt;&lt;BR /&gt;%SHOW-W-NOAUDITING, security auditing disabled; no events will be logged&lt;BR /&gt;ALPHAC&amp;gt;&lt;BR /&gt;&lt;BR /&gt;thanks for helping!&lt;BR /&gt;Clark Powell&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Sep 2008 13:48:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271483#M92232</guid>
      <dc:creator>Clark Powell</dc:creator>
      <dc:date>2008-09-18T13:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271484#M92233</link>
      <description>You &lt;BR /&gt;&lt;BR /&gt;*must*&lt;BR /&gt;&lt;BR /&gt;set up the logical names per &lt;BR /&gt;&lt;BR /&gt;SYLOGICALS.TEMPLATE&lt;BR /&gt;&lt;BR /&gt;in an OpenVMS cluster.&lt;BR /&gt;&lt;BR /&gt;Yes, OpenVMS might &lt;BR /&gt;&lt;BR /&gt;*appear* &lt;BR /&gt;&lt;BR /&gt;to work if you don't have all the right logical names and the files configured and shared (or -- in the case of a multiple-SYSUAF cluster -- carefully synchronized), but weirdness then tends to ensue.&lt;BR /&gt;&lt;BR /&gt;I'm the perpetrator of that list of logical names, and I implemented that specifically because folks with multiple system disks inevitably got it wrong.  (Until I put that list together, *I* got it wrong.)  And weirdness ensued.  Multiple system disk configurations are particularly prone to weirdnesses.&lt;BR /&gt;&lt;BR /&gt;For the shared files on (I assume) a shared I/O bus, make sure you have the disks mounted at the appropriate place in startup; early on.  (I'm assuming a shared I/O bus is present because a two-node cluster is pretty hairy otherwise.  And it's way more work.)&lt;BR /&gt;&lt;BR /&gt;If you *do* have these logical names defined and the cluster configured properly (and congrats; that's not easy!), then the next step is to take a look around for audit server dump files, or for whatever is causing the audit server to tip over.  DIR SYS$SYSROOT:[*...]*.DMP /SINCE or such, and check the accounting data (ACCOUNT /SINCE=last-boot-time-and-date /FULL SYS$MANAGER:ACCOUNTNG.DAT or such)&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Sep 2008 13:58:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271484#M92233</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2008-09-18T13:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271485#M92234</link>
      <description>And my 4) ?&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 18 Sep 2008 14:13:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271485#M92234</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-09-18T14:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271486#M92235</link>
      <description>Clark,&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;&lt;BR /&gt;there are two nodes, two separate system disk, logical VMS$AUDIT_SERVER defined on both nodes,&lt;BR /&gt;&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;&lt;BR /&gt;Did you perhaps fall for the trap of having those defined as somehow derived from SYS$SYSDEVICE or SYS$SYSROOT?&lt;BR /&gt;(I once made that mistake also, and it puzzled me much, until the famous "Oh no, not THAT simple" experience.) &lt;BR /&gt;Those ARE the default definitions, but, in a multi-systemdisk cluster, they point to DIFFERENT devices! Be sure to use LNMs derived from the SAME device, and have that device MOUNTed (for EACH node) by SYLOGICALS.COM&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Thu, 18 Sep 2008 14:36:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271486#M92235</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2008-09-18T14:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271487#M92236</link>
      <description>Clark,&lt;BR /&gt;&lt;BR /&gt;Here is what the security manual says, which is different than what sylogicals suggests.&lt;BR /&gt;&lt;BR /&gt;HP OpenVMS Guide to System Security&lt;BR /&gt;OpenVMS Version 7.3-2&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/732FINAL/aa-q2hlg-te/AA-Q2HLG-TE.pdf" target="_blank"&gt;http://h71000.www7.hp.com/doc/732FINAL/aa-q2hlg-te/AA-Q2HLG-TE.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Chapter 9 Security Auditing pg 204&lt;BR /&gt;-------------------------------------------------------------------------------------------------------&lt;BR /&gt;Moving the File from the System Disk&lt;BR /&gt;To relocate the file from the SYS$COMMON:[SYSMGR] directory, edit the command procedure&lt;BR /&gt;SYSECURITY.COM. This procedure executes each time the system is rebooted, before the audit server is&lt;BR /&gt;started.&lt;BR /&gt;To relocate the file, perform the following steps:&lt;BR /&gt;1. Change the startup sequence by adding a line to SYSECURITY.COM that directs the operating system to&lt;BR /&gt;mount the designated auditing disk before the audit server process is started rather than after. For&lt;BR /&gt;example:&lt;BR /&gt;$ IF .NOT. F$GETDVI("$1$DUA2","MNT") -&lt;BR /&gt;_$ THEN MOUNT/SYSTEM $1$DUA2 AUDIT AUDIT$ /NOREBUILD&lt;BR /&gt;The command in this example mounts a volume labeled AUDIT on $1$DUA2 and makes it available&lt;BR /&gt;systemwide. MOUNT also assigns the logical name AUDIT$.&lt;BR /&gt;2. Move the audit server database to the auditing disk, if you choose. The database remains small and fairly&lt;BR /&gt;stable so this step is not essential.&lt;BR /&gt;To move the database, add a second line to SYSECURITY.COM to define the system logical name&lt;BR /&gt;VMS$AUDIT_SERVER. (The line follows the one that mounts the auditing disk.) In the command, define&lt;BR /&gt;a system logical name and assign it to the VMS$AUDIT_SERVER data file on the disk with the logical&lt;BR /&gt;name AUDIT$. For example:&lt;BR /&gt;$ DEFINE/SYSTEM/EXEC VMS$AUDIT_SERVER AUDIT$:[AUDIT]VMS$AUDIT_SERVER.DAT&lt;BR /&gt;This command redirects the audit server database to the volume on $1$DUA2, which was mounted in&lt;BR /&gt;step 1.&lt;BR /&gt;3. From the DCL level, redirect the security audit log file to the volume mounted in SYSECURITY.COM (see&lt;BR /&gt;step 1). Use the SET AUDIT command to update the audit server database with the new location of the&lt;BR /&gt;security audit log file, and instruct the audit server process on each node in the cluster to begin using the&lt;BR /&gt;file. For example:&lt;BR /&gt;$ SET AUDIT/JOURNAL=SECURITY -&lt;BR /&gt;_$ /DESTINATION=AUDIT$:[AUDIT]SECURITY&lt;BR /&gt;Do not repeat this command on each system restart.&lt;BR /&gt;If you use a logical name in the specification of the security audit log file, it must be defined as a&lt;BR /&gt;/SYSTEM logical name in SYSECURITY.COM.&lt;BR /&gt;-------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Also see section "Managing the Auditing Subsystem" starting on page 212.&lt;BR /&gt;&lt;BR /&gt;You currently have multiple audit journal files, since each system disk has its own sys$common.  Accourding to the manual, that will work, but is not recommended:  (from page 203)&lt;BR /&gt;&lt;BR /&gt;-------------------------------------------------------------------------------------------------------&lt;BR /&gt;Ordinarily, all cluster events are written to a single audit log file. The use of one security audit log file in a&lt;BR /&gt;cluster results in a single record of all security-relevant events on the system. For this reason, one clusterwide&lt;BR /&gt;log file is preferable to node-specific audit logs, which lose the interrelationship of events across the cluster,&lt;BR /&gt;thus producing an incomplete analysis of security events. You can, if you wish, create node-specific audit logs&lt;BR /&gt;(see Maintaining the File), but this is not the recommended procedure. &lt;BR /&gt;-------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;One more thing, set audit/start does not do everything needed to start auditing.  You must do that, wait for the AUDSRV$CONTROL_MAILBOX to be created, then issue set audit/initiate.  Or do what is recommended and use&lt;BR /&gt;&lt;BR /&gt;$ @SYS$SYSTEM:STARTUP AUDIT_SERVER&lt;BR /&gt;&lt;BR /&gt;(See help set audit/server)&lt;BR /&gt;&lt;BR /&gt;Jon</description>
      <pubDate>Thu, 18 Sep 2008 16:09:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271487#M92236</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-18T16:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271488#M92237</link>
      <description>SYLOGICALS.COM mounts the disk which has the common logical name definition file and executes it and also is the target of the audit server (now.)  This disk has other important files like SYSUAF.DAT so nothing would work if it was not commonly accessible.  So that criteria is met.  &lt;BR /&gt;    There are no messages in operator.log that relate to audit server.&lt;BR /&gt;    Audit server processes run on both nodes as shown:&lt;BR /&gt;ALPHAZ&amp;gt; PIPE SHO DEVICE/FILE DSA10: | SEA SYS$INPUT 218455CE&lt;BR /&gt;AUDIT_SERVER    218455CE  [VMS$COMMON.SYSEXE]AUDIT_SERVER.EXE;1&lt;BR /&gt;ALPHAZ&amp;gt; PIPE SHO DEVICE/FILE DSA200: | SEA SYS$INPUT 218455CE&lt;BR /&gt;AUDIT_SERVER    218455CE  [VMCOMMON]VMS$AUDIT_SERVER.DAT;1&lt;BR /&gt;AUDIT_SERVER    218455CE  [VMCOMMON]SECURITY.AUDIT$JOURNAL;5&lt;BR /&gt;AUDIT_SERVER    218455CE  [VMCOMMON]VMS$OBJECTS.DAT;1&lt;BR /&gt;&lt;BR /&gt;    After reading the last comments I decided that maybe the journal HAD to be shared so I used a definition that would equate to the same location for BOTH nodes.  This only changed the journal entry in SHOW AUDIT/JOURNAL &lt;BR /&gt;&lt;BR /&gt;ALPHAZ&amp;gt; sho audit/jou&lt;BR /&gt;List of audit journals:&lt;BR /&gt;  Journal name:           SECURITY&lt;BR /&gt;  Journal owner:          (system audit journal)&lt;BR /&gt;  Destination:            SYSDISK2:[VMCOMMON]SECURITY.AUDIT$JOURNAL&lt;BR /&gt;  Monitoring:             enabled&lt;BR /&gt;    Warning thresholds,   Block count:    100     Duration:    2 00:00:00.0&lt;BR /&gt;    Action thresholds,    Block count:     25     Duration:    0 00:30:00.0&lt;BR /&gt;&lt;BR /&gt;%SHOW-W-NOAUDITING, security auditing disabled; no events will be logged&lt;BR /&gt;&lt;BR /&gt;   My guess is that the VMS$AUDIT_SERVER.DAT might be corrupted and require being recreated.  (But, I don't know if the audit server would automatically do this if those files were missing....&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Sep 2008 16:27:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271488#M92237</guid>
      <dc:creator>Clark Powell</dc:creator>
      <dc:date>2008-09-18T16:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271489#M92238</link>
      <description>Clark,&lt;BR /&gt;&lt;BR /&gt;Just to confirm: you did &lt;BR /&gt;&lt;BR /&gt;$ set audit/initialize&lt;BR /&gt;&lt;BR /&gt;or &lt;BR /&gt;&lt;BR /&gt;$ @SYS$SYSTEM:STARTUP AUDIT_SERVER&lt;BR /&gt;&lt;BR /&gt;after making your changes?&lt;BR /&gt;&lt;BR /&gt;If your VMS$AUDIT_SERVER.DAT was corrupt, why is one node's audit server working correctly?&lt;BR /&gt;&lt;BR /&gt;The data in this file is normally static, so you should be able to copy the working version to the shared directory using convert/share.  My guess is that it is not the file, but that the /initialize needs to be done.&lt;BR /&gt;&lt;BR /&gt;Reference: &lt;A href="http://h71000.www7.hp.com/wizard/wiz_8897.html" target="_blank"&gt;http://h71000.www7.hp.com/wizard/wiz_8897.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Jon</description>
      <pubDate>Thu, 18 Sep 2008 18:27:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271489#M92238</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-18T18:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271490#M92239</link>
      <description>CONCLUSION:&lt;BR /&gt;&lt;BR /&gt;    Having SECURITY.AUDIT$JOURNAL in different locations for each node didn't work.  I had to execute this command:&lt;BR /&gt;Set audit/DESTINATION=SYSDISK2:[VMCOMMON]SECURITY.AUDIT$JOURNAL/JOUR=SECURITY&lt;BR /&gt;&lt;BR /&gt;and then I HAD to restart using &lt;BR /&gt;@SYS$SYSTEM:STARTUP AUDIT_SERVER &lt;BR /&gt;not &lt;BR /&gt;SET AUDIT/SERVER=START&lt;BR /&gt;&lt;BR /&gt;  collecting audit data now...&lt;BR /&gt;&lt;BR /&gt;thanks everyone, the forum is working better than some of the HP support I've been getting lately.  &lt;BR /&gt;Clark</description>
      <pubDate>Thu, 18 Sep 2008 19:03:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271490#M92239</guid>
      <dc:creator>Clark Powell</dc:creator>
      <dc:date>2008-09-18T19:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271491#M92240</link>
      <description>Sorry for the incorrect syntax I had.&lt;BR /&gt;&lt;BR /&gt;As Clark posted, the correct set audit syntax is &lt;BR /&gt;&lt;BR /&gt;$ set audit /SERVER=[start|initialize]&lt;BR /&gt;&lt;BR /&gt;I left out the "/SERVER=" part in my recommendation.  &lt;BR /&gt;&lt;BR /&gt;zero points for this.</description>
      <pubDate>Fri, 19 Sep 2008 03:19:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271491#M92240</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-19T03:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271492#M92241</link>
      <description>I don't get it. How can you have 2 different destinations when you have 1  vms$audit_server.dat ?&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Fri, 19 Sep 2008 07:46:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271492#M92241</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-09-19T07:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271493#M92242</link>
      <description>RE:"How can you have 2 different destinations when you have 1 vms$audit_server.dat ?"&lt;BR /&gt;&lt;BR /&gt;If the journal file is set to Destination: SYS$COMMON:[SYSMGR]SECURITY.AUDIT$JOURNAL and you have two different system disks, or if is is set to Destination: SYS$SPECIFIC:[SYSMGR]SECURITY.AUDIT$JOURNAL and you have a shared system disk. Those are two ways I can think of.  Although the logical specifications are the same, they will be distinct files.&lt;BR /&gt;&lt;BR /&gt;Jon&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Sep 2008 08:37:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271493#M92242</guid>
      <dc:creator>Jon Pinkley</dc:creator>
      <dc:date>2008-09-19T08:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: %SHOW-W-NOAUDITING, security auditing disabled; no events will be logge</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271494#M92243</link>
      <description>Jon,&lt;BR /&gt;&lt;BR /&gt;Sorry I was incomplete but I saw the file on dsa200 not being the system disk. So, that should be shared.&lt;BR /&gt;&lt;BR /&gt;I just did a test with 1 vms$audit_server.dat file common for both nodes. No problem at all for getting destination to 2 different disk (destination a:[000000]wim.lis where a is the local page file of both systems, not mounted by each other).&lt;BR /&gt;&lt;BR /&gt;Wrong conclusion ?&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Fri, 19 Sep 2008 09:39:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/show-w-noauditing-security-auditing-disabled-no-events-will-be/m-p/4271494#M92243</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-09-19T09:39:08Z</dc:date>
    </item>
  </channel>
</rss>

