To enhance the security of systems and applications, administrators often need to know whether users have deleted specific files. The following describes how to achieve the Administrator's goal through system audit.
The system security audit function allows you to manage system security with minimal system overhead. It only records object change events and does not record detailed data in the object.
The following is the system setting method:
1. Run the go sectools command to Display the * Display the Security Tools Menu.
2. select option 10: Change Security Auditing
3. Change the system value QAUDCTL to * OBJAUD and QAUDLVL to * DELETE. Press enter.
4. If the security audit log does not exist in the system at this time, the system will create it.
5. Run the command CHGOBJAUD to change the object audit.
6. In the CHGOBJAUD parameter, enter the name of the object you want to audit. Fill in * change at the parameter objaud.
7. Repeat steps 5-6 to add the object you want to audit.
8. The created log is displayed. After running the go sectools command, select option 22.
9. Fill in "DO" in the ENTTYP parameter -- it will record who, when, and what object has been deleted