The following variables are available for all types of security events:
The authorization string of the CA OPS/MVS installation
Data Type: Character, read-only
Source: The value of the CA OPS/MVS AUTHSTRING parameter (described in the Parameter Reference)
Sample Value: TRIAL
Indicates whether security processing should be bypassed.
Data Type: Bit, read-only
Source: The CA OPS/MVS component indicates whether security is bypassed.
Sample Value: 1
Note: This flag is true for the CA OPS/MVS main address space and for AOF rules.
Indicates whether the current address space is an ECF user.
Data Type: Bit, read-only
Source: The CA OPS/MVS component indicates the address space type.
Sample Value: 1
The error message text
Data Type: Character, read/write
Source: Other security rules
Sample Value: 'You are not allowed to use OPSCMD'
Notes:
Indicates that the CA OPS/MVS authorization routine (OPAUCK) can produce error messages.
Data Type: Bit, read-only
Source: The CA OPS/MVS component that calls OPAUCK.
Sample Value: 1
The current job name that the ASCB points to
Data Type: Character, read-only
Source: The ASCBJBNI field for batch jobs, or the ASCBJBNS field for other address spaces
Sample Value: USERA
Indicates whether the current address space is the main CA OPS/MVS product address space.
Data Type: Bit, read-only
Source: The CA OPS/MVS component indicates the address space type.
Sample Value: 1
Indicates whether the current address space is an OSF server.
Data Type: Bit, read-only
Source: The CA OPS/MVS component indicates the address space type.
Sample Value: 1
The return code from the current access request
Data Type: Integer, read-only
Source: Set by authorization components
Possible Values:
Sample Value: 8
The type of access request
Data Type: 1 to 10 characters, right-justified, read-only, padded with blanks
Source: The CA OPS/MVS component that calls OPAUCK.
Possible Values:
ADDRESS AP Host command
Attempt to generate an event to the Generic Event API.
ADDRESS AOF command
OPSLOG Browse request
OPSCMD/ADDRESS OPER (MVS, VM, JES3, IMS CMD)
ADDRESS OPSCTL (MSF, OSF, ECF) request
OPSDOM (DOM A MESSAGE) request
ADDRESS EPI command or EPI request
Global or Sysplex variable access/update request
SHARED file I/O request
OPSLOG API request
OPSOSF request (OSF command request)
OPSPARM (SET PARAMETERS) request
OPSREPLY (WTO/WTOR) request
Attempt to execute a REQUEST Rule.
SEND a command to a server request
STATETBL request
OPSVIEW request
OPSWTO/ADDRESS WTO (WTO, WTP, WTOR) request
ADDRESS SOF request
SQL/RDF request
Subsystem data set open request
ADDRESS USS command
Sample Value: SQL. When OPAUQRTY is blank, OPAUTRTX must be checked for a valid security type.
The type of access request
Data Type: Character, read-only
Source: The CA OPS/MVS component that calls OPAUCK.
Possible Values:
ADDRESS AP Host Command
OPSVIEW request
OPSLOG Browse request
OPSEPI request
Automated Operations Facility request
OPSOSF request
OPSDOM request
OPSCTL request
OPSLOG API request
OPSRMT request
USS request
OPSCMD request
OPSPARM request
OPSREQ request
OPSREPLY request
SQL request
Global and Sysplex variable access/update request
OPSWTO request
Subsystem data set open request
OPSSMTBL request
OPSHFI request
Sample Value: A
Notes:
The CA OPS/MVS subsystem name to which the request was directed.
Data Type: Character, read-only
Source: Subsystem to which the request was directed.
Sample Value: OPSS
Note: You can use this variable to create a security rule that works on multiple subsystems (for example, a production and a test system).
The CA ACF2/CA Top Secret/RACF logon ID for this request
Data Type: Character, read-only
Source: The SAF user ID associated with the current task or address space
Sample Value: USERA
|
Copyright © 2014 CA.
All rights reserved.
|
|