RACF profile usage not logged in SMF dataset



All about SAF, RACF, encryption, Firewall, Risk assessment and integrity concepts

RACF profile usage not logged in SMF dataset

Postby aarvalar1 » Wed May 01, 2024 7:35 pm

I am looking for the STGADMIN FACILITY profile usage for the past one month. So ran the IFASMFDP utility to unload the SMF logs for the past one month but unable to find the dataset which is accessed by the production batch jobs stored in the SMF logs. I am not sure where the problem lies (or) from where to start to fix this issue. Can someone assist me on this please?
aarvalar1
 
Posts: 18
Joined: Fri Apr 14, 2023 3:12 pm
Has thanked: 4 times
Been thanked: 0 time

Re: RACF profile usage not logged in SMF dataset

Postby Robert Sample » Thu May 02, 2024 7:36 pm

SMF type 80 records store RACF data. AFAIK, as a general rule successful accesses are not logged in SMF nor anywhere else. Also, I don't think FACILITY usage is logged anywhere.
unable to find the dataset which is accessed by the production batch jobs
It is not clear what dataset you are looking for here.
Robert Sample
Global moderator
 
Posts: 3720
Joined: Sat Dec 19, 2009 8:32 pm
Location: Dubuque, Iowa, USA
Has thanked: 1 time
Been thanked: 279 times

Re: RACF profile usage not logged in SMF dataset

Postby aarvalar1 » Fri May 03, 2024 3:23 pm

Thanks for the reply Robert.
I am trying to limit access to STGADMIN. ** profile.
Currently there are way too much access to that profile.
Before limiting the access I would like to know if any production batch IDs require access. So I was looking into SMF logs for the profile usage.
In the logs, I can see that profile was accessed by some user accounts but not showing any batch IDs.

So we restricted the access only to storage people on test system but end up with access violation for the batch ID.
Before moving to production, need some clarification on this.
aarvalar1
 
Posts: 18
Joined: Fri Apr 14, 2023 3:12 pm
Has thanked: 4 times
Been thanked: 0 time

Re: RACF profile usage not logged in SMF dataset

Postby Robert Hansel » Sat May 11, 2024 9:32 pm

Did you add AUDIT(ALL(READ)) to your STGADMIN profiles to log all access activity?

Alternatively, if you have IBM's zSecure Admin product and have implemented the Access Monitor component, you can use Access Monitor data to report on access activity.
Regards, Bob

Robert S. Hansel
Lead RACF Specialist
RSH Consulting, Inc.
617-969-8211
www.linkedin.com/in/roberthansel
www.rshconsulting.com
Robert Hansel
 
Posts: 12
Joined: Fri Sep 17, 2010 12:24 am
Has thanked: 0 time
Been thanked: 4 times


Return to Mainframe Security

 


  • Related topics
    Replies
    Views
    Last post