![]() | |
![]() |
| | Thread Tools | Display Modes |
#1
| |||
| |||
|
#2
| |||
| |||
|
|
Hi All. I'm trying to trace a user who keeps stufffing up their username and password. Sadly this isn't as easy as it seems…. The errlog is filled with messages like: E_GC000E_RMT_LOGIN_FAIL_INFO A remote login attempt failed. The remote machine was 'brat.ctsu.ox.ac.uk', and the userid was 'ingres'. The trouble is that the 'remote machine' mentioned here is actually the local host, whch given that the username is a generic account, is making this a tad tricky to track down. I've enable security_audit User, database. But the user details are not being captured…presumbly as the user never manages to authenticate the system is not writing an entry into iiaudit. I only seem to catch detailsin iiaudit for auditevent = 'AUTHENTICATE' with auditstatus = 'Y'. I've tried monkeying with gca tracing but to no avail. I've tried monkeying with IMA, to no avail. I'm pretty sure that this is a VDBA connection coming in from a PC. So what I would like is for the errlog string to contain the PC name or IP. I would also like to see some residue in iiaudit that indicates an authentication failed. Is this a bug or am I doing something wrong? Is there an easier way? Martin Bowes _______________________________________________ Info-Ingres mailing list Info-Ingres (AT) kettleriverconsulting (DOT) com http://ext-cando.kettleriverconsulti...fo/info-ingres |
#3
| |||
| |||
|
![]() |
| Thread Tools | |
| Display Modes | |
| |