Overview
Further Information
Trial
Buy
Use
|
|
|
Audit Journal Manager
Introduction
Audit Journal Manager is a specialist utility for the real-time alerting and reporting from the audit journal for the IBM i (iSeries) which also assists with intrusion detection.
Audit Journal Manager provides real-time monitoring, alerting and reporting of the i5/OSĀ© system audit journal, QAUDJRN; the key place for logging security related events. Systems administrators can define the type of events they want to monitor and the Halcyon Audit Journal Manager will proactively monitor the
journal for these events and automatically perform pre-defined actions.
Run customized reports based upon specific audit criteria or use any of the 34 pre-configured reports to get a detailed view of user activity within QAUDJRN.
Features
-
Monitors for the arrival of different types of journal entries in the system audit journal QAUDJRN
-
Comprehensive filters can be set up to ignore unimportant entries while quickly alerting you to important entries of which you need to be made aware
-
Escalating actions can be defined to draw your attention to critical events
-
Substitution variables can be used to pass variable information for easy and accurate command execution
-
An unlimited number of actions can be performed in any pre-defined sequence when your selected journal entries are received by the system
-
Messages can be sent directly into the Halcyon Enterprise Console when a graphical centralized management tool is required
|
Benefits
-
Analyze and monitor changes made to user profiles, such users changing their authority to *SECADM for example
-
Quickly detect when invalid attempts are made to sign on - especially if this happens to be QSECOFR
-
Changes to your system values can be tracked and traced as these can have a significant impact on areas of security and system performance
-
Be informed when sensitive objects (such as the Payroll file) are created, deleted, restored, moved or renamed or ownership to that object or access rights are changed
-
Authority failures can be detected and brought to someone's immediate attention. For example, a user might be attempting to access an object that they are not authorized to, such as the supplier master file
-
Keep an eye on user profile swapping and be kept informed about what is happening on your system
|
|
|
|
  
Did you know the Audit Journal Manager module is available in the following software suites?
Level 2

Level 3

Level 4

|