Skip to main content

Failed Login by Source

Lists failed login events, grouped by IP address, terminal or application name.

This report reads TCP/IP SMF records to attempt to relate the terminal id from the RACF record to an IP address.

Columns

ColumnDescription
SourceThe source of the failed login. This could be (in order of preference): 1.The IP address, if it could be determined from the TCP/IP SMF records2.The terminal ID3.The job name
CountThe number of events from this source
TimeEvent time
SystemSystem (SMF ID) that wrote the record
UserRACF userid
GroupRACF group
Job NameJob name
QualifierRACF event qualifier
DescriptionRACF event qualifier description
TerminalThe terminal ID
IP AddressIP address if it could be determined
ApplicationApplication name
LOGSTRLOGSTR specified by the application

Report Parameters

ParameterDescription
SystemThe SMF ID of the system that wrote the record.
UseridFilter by userid
JobnameFilter by job name
TerminalFilter by terminal ID
IP AddressFilter by IP address

SMF records used for this report

TypeSubtype
80
1191 - Connection initiation
1192 - Connection termination
11920 - TN3270 SNA session initiation
11921 - TN3270 SNA session termination