Angus,

The ones I see most often are Client Access type connections which are 
connected as QUSER prior to users authentication.  The user FERNJ might have 
been attempting to changed their password or didn't type it in correctly and it 
was disabled.  It was QUSER that did the change password or disabled the 
profile.

Look at your audit journals directly using DSPAUDJRNE ENTTYP(CP) and you should 
see more detail on what was actually changed for the user profile FERNJ.

Ken H.

-----Original Message-----
From: midrange-l-bounces@xxxxxxxxxxxx
[mailto:midrange-l-bounces@xxxxxxxxxxxx]On Behalf Of Angus MacQueen
Sent: Thursday, March 01, 2007 7:30 AM
To: midrange-l@xxxxxxxxxxxx
Subject: Audit Journal Entry


Can anyone explain the circumstances where the QUSER profile might be
responsible for changing a USRPRF?

We have a piece of software that monitors the audit journal and if necessary
logs an alert by email, sms, and/or to a console and I want to consider
whether to exclude this alert if the profile is QUSER.

This is an example of the alert I get:-

Event message . . . . . :  CP - User Profile FERNJ changed by QUSER.

User profile  . . . . . :  FERNJ
Job . . . . . . . . . . :  687789/QUSER/QZSOSIGN

TIA


Angus

As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.