Lists failed login events, grouped by IP address, terminal or application name.
This report reads TCP/IP SMF records to attempt to relate the terminal id from the RACF record to an IP address.
Columns
| Column | Description |
|---|
| Source | The source of the failed login. This could be (in order of preference): 1.The IP address, if it could be determined from the TCP/IP SMF records2.The terminal ID3.The job name |
| Count | The number of events from this source |
| Time | Event time |
| System | System (SMF ID) that wrote the record |
| User | RACF userid |
| Group | RACF group |
| Job Name | Job name |
| Qualifier | RACF event qualifier |
| Description | RACF event qualifier description |
| Terminal | The terminal ID |
| IP Address | IP address if it could be determined |
| Application | Application name |
| LOGSTR | LOGSTR specified by the application |
Report Parameters
| Parameter | Description |
|---|
| System | The SMF ID of the system that wrote the record. |
| Userid | Filter by userid |
| Jobname | Filter by job name |
| Terminal | Filter by terminal ID |
| IP Address | Filter by IP address |
SMF records used for this report
| Type | Subtype |
|---|
| 80 | |
| 119 | 1 - Connection initiation |
| 119 | 2 - Connection termination |
| 119 | 20 - TN3270 SNA session initiation |
| 119 | 21 - TN3270 SNA session termination |