Do you have an idea of what kind of entries are being deposited into the Audit Journal ?
For example .... Here is what is being put into mine over the last few hours....
Code Type Count
J PR 1 ID for previous journal receiver
T AD 4
T AF 3
T AP 258
T CA 32,836
T CD 94,764
T CO 7,120
T DI 16 Directory services
T DO 7,152
T GR 14
T GS 585
T IP 5,044
T JS 71,450
T LD 6,769
T OM 596
T OW 439
T PG 3
T PO 90
T PS 1,483
T SF 1,171
T SG 425 Asynchronous signals
T SM 8
T ST 1
T VO 8
T ZC 541
U EN 1 User defined
U NA 500,896 User defined
U TA 1,988 User defined
733,666
Kenneth
Kenneth E. Graap
http://www.linkedin.com/in/kennethgraap
-----Original Message-----
From: midrange-l-bounces@xxxxxxxxxxxx [mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of Ryan Hunt
Sent: Wednesday, November 17, 2010 11:53 AM
To: midrange-l@xxxxxxxxxxxx
Subject: QAUDJRN and QAUDLVL
We recently moved from a V5R4 server to a V6R1 server. As part of my
security monitoring we audit *AUTFAIL and *SECURITY (QAUDLVL) to the QAUDJRN
journal. I don't have my old server anymore so I can't confirm this for
sure, but I'm pretty sure my setup for V5R4 was exactly the same.
I'm finding that while my V5R4 server kicked out a 100MB journal receiver
every 2 or 3 days, my V6R1 server is kicking out a 1.5GB file every single
day.
Has anyone else seen this behavior?
As an Amazon Associate we earn from qualifying purchases.