Lists events with elevated access authority used flags (SPECIAL, ROAUDIT/OPERATIONS, AUDITOR, installation exit, failsoft, *BYPASS*, TRUSTED, superuser or UNIX system) set in the RACF SMF records.
Columns
| Column | Description |
|---|
| Time | Event time |
| System | System (SMF ID) that wrote the record |
| User | RACF userid |
| Job Name | Job name |
| Access | The elevated access flags that were set |
| Event | RACF event |
| Class | RACF class |
| Resource | RACF resource, data set, file etc. or target of the event |
| Requested | Requested access |
Report Parameters
| Parameter | Description |
|---|
| System | The SMF ID of the system that wrote the record. |
| Userid | Filter by userid |
| Jobname | Filter by job name |
| Event | Filter by event |
| Class | Filter by RACF class |
| Resource | Filter by resource name |
| All | Check/uncheck all the following boxes: |
| Special | Events with SPECIAL flag |
| Operations | Events with OPERATIONS or ROAUDIT flag |
| Auditor | Events with AUDITOR flag |
| Exit | Events with installation exit processing flag |
| Failsoft | Events with failsoft processing flag |
| Bypass | Events with *BYPASS* bypassed user flag |
| Trusted | Events with Trusted attribute flag |
| Superuser | Events with UNIX superuser flag |
| Unix System | Events with UNIX system function flag |
SMF records used for this report