Previous Topic: CA Audit FieldsNext Topic: Taxonomy Fields


Mandatory Fields

Mandatory fields are a fixed set of fields that are added to each event processed by any iRecorder. The following table describes the values that are assigned to the mandatory fields in the SiteMinder Web Access Manager.

Field

Default Value

Description

Taxonomy

<Category>.<System>.<Action>.<Result>.<Severity>

For details, see About Taxonomy Fields.

Date

Time when the event is received by the iRecorder

The timestamp of the event in time_t format(number of seconds since 1/1/1970 12am UTC).

TimeZone

Timezone of the iRecorder host

Local time zone of the event in number of seconds. Local time zone is the difference between the local time and UTC. For example, if the event is recorded in the US East Coast, the TimeZone during daylight saving time it will be –14400 (or -4 hours), for other times it will be –18000 (or –5 hours.)

Src

SiteMinder

Name of the component (device, application, or product) that generated the event.

Log

Sm Access for runtime access control events

Sm Object for administrative/management events

Logical name of the system/device/file (if any) where the events were stored by original issuer.

Location

None

Hostname or IP address of the Source system

Recorder

SmRecorder

Name of the recorder that captured the event. Specified in the source code of iRecorder.

RecorderHost

Unknown

FQDN (fully qualified domain name) of the host running the iRecorder. Consists of a host and domain name, including top-level domain. For example, www.webopedia.com is a fully qualified domain name. www is the host, webopedia is the second-level domain, and.com is the top level domain.

A FQDN always starts with a host name and continues all the way up to the top-level domain name, so www.parc.xerox.com is also a FQDN.

Note: The Log field displays the SM Access and SM Object entries. Please note that these values show the resource accessed, rather than the computer name accessed, since multiple databases can be accessed from the same computer. For example, the resource location in Oracle is specified by the appropriate TNS service name.