Each event expresses information about two actors: the Source and the Destination.
The source actor can be a user, source_username, or a process, source_processname.
The destination actor can be a user, dest_username, or an object, dest_objectname.
The User prompt queries for events where the actor you specify appears in the selected CEG fields of the refined event. Consider this scenario:
To use the User prompt
The Query List displays the Prompts folder and one or more folders for other queries.
The User prompt appears.
Is the name of the user that initiated the event action.
Is the name of user that is the target of the action.
Is the name of the object involved in the action referenced in event information.
Is the name of the object that is the target of the action.
Results of the User prompt query appear.
Indicates the severity of the event, where the values in increasing order of severity include: Information, Warning, Minor Impact, Major Impact, Critical, and Fatal.
Indicates when the event occurred.
Identifies the name of the host with the user who was the target of the event action.
Specifies a code for the event result of the corresponding action, where S means Success, F means Failure, A means Accepted, D means Dropped, R means Rejected, and U means Unknown.
Identifies the user who initiated the event action.
Identifies the object on the source host that was involved in the event action.
Identifies the user who was the target of the event action.
Identifies the object on the destination host that was involved in the event action.
Identifies the high-level category of the corresponding event action. For example, System Access is the category for the Authentication action.
Identifies the event action.
Identifies the log name used by the connector that collected the event.
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |