Previous Topic: Facilities Class XREFNext Topic: Security Events


Sources

Source Groups control from which terminals (sources) a user can access the system.

The Sources category lets you view different queries for the CIA SRCREC table:

All Records

Displays all records in the SRCREC table: System ID (SYSID), Record ID (SRCRECID), Source Group (SRCGRP), Source Name/Mask (SRCMASK), Record Type (RECTYPE), Include/Exclude Indicator (INCLEXCL), Source Type (SRCTYPE).

Source Groups

Displays distinct System ID, Source Group, Record Type and Source Type records from the SRCREC table: System ID (SYSID), Source Group (SRCGRP), Record Type (RECTYPE), Source Type (SRCTYPE).

ACF2 ESRC Sources

Displays all records in the SRCREC table for ESRC records (Record Type “E”): Displays System ID (SYSID), Source Group (SRCGRP), and Source Name/Mask (SRCMASK). Use this query to map logical source names (for example, "shipping1") to physical source names (for example, "LV396").

Note: After you select a row of data, more granular information appears in the Details pane at the bottom of the Investigator.

Example: Inspect source access restrictions for users

You want to know which users have CA Top Secret source restrictions.

  1. Filter Source Groups for the CA Top Secret System ID.

    The grid displays all the users (Source Groups).

  2. Click the action “Show Entries” to inspect the sources for a user.

Example: Inspect which source groups exist.

You want to know which CA ACF2 Source Groups exist.

  1. Filter Source Groups for the CA ACF2 System ID.

    The grid displays all the Source Groups.

  2. Click the action “Show Entries” to inspect the sources in the source group.

Example: Inspect who uses a source

You want to know where a source "abc" is used. Filter All Records for:

“Source Name/Mask” = abc

The grid displays all the groups (CA ACF2) or Users (CA Top Secret) that use this source.