You can use a predefined query to create an alert when group memberships are added or removed by a member of a privileged group. You can use the default keyed list only or you can supplement it with your own values. Predefined values include dba, mail, ORA_DBA, sshd, uucp, and wheel.
To customize the list, you identify other accounts as values in the key-value list for Privileged_Groups.
The queries that use the values you supply include:
If you create a custom query that uses this key, define the filter as follows:
Column |
Operator |
Value |
---|---|---|
dest_groupname |
Keyed |
Privileged_Groups |
To customize keyed values for Privileged_Groups
A list of keys to which you add user-defined values is displayed at the bottom of the main pane.
If you have already scheduled an action alert with one of the queries that uses the Privileged_Groups keyed list, that alert will be generated based on the evaluation of values in your modified keyed list.
Copyright © 2010 CA. All rights reserved. | Email CA Technologies about this topic |