<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.vmssoftware.com/index.php?action=history&amp;feed=atom&amp;title=ANALYZE%2FAUDIT</id>
	<title>ANALYZE/AUDIT - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.vmssoftware.com/index.php?action=history&amp;feed=atom&amp;title=ANALYZE%2FAUDIT"/>
	<link rel="alternate" type="text/html" href="https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;action=history"/>
	<updated>2026-05-02T18:26:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.3</generator>
	<entry>
		<id>https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;diff=2448&amp;oldid=prev</id>
		<title>Junji: add Category:DCL Commands</title>
		<link rel="alternate" type="text/html" href="https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;diff=2448&amp;oldid=prev"/>
		<updated>2021-11-26T02:26:10Z</updated>

		<summary type="html">&lt;p&gt;add Category:DCL Commands&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 02:26, 26 November 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l457&quot;&gt;Line 457:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 457:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Utilities]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Utilities]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:DCL Commands]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Junji</name></author>
	</entry>
	<entry>
		<id>https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;diff=493&amp;oldid=prev</id>
		<title>Darya.zelenina: added the See also section and the category link</title>
		<link rel="alternate" type="text/html" href="https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;diff=493&amp;oldid=prev"/>
		<updated>2019-04-05T18:08:54Z</updated>

		<summary type="html">&lt;p&gt;added the See also section and the category link&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:08, 5 April 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l452&quot;&gt;Line 452:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 452:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| Specifies the target process identifier (PID) used by a process control system service.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| Specifies the target process identifier (PID) used by a process control system service.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=See also=&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* {{Template:UtilitiesI}} for use instructions and command dictionary&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Utilities]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Darya.zelenina</name></author>
	</entry>
	<entry>
		<id>https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;diff=398&amp;oldid=prev</id>
		<title>Darya.zelenina: Created page with &quot;&#039;&#039;&#039;ANALYZE/AUDIT&#039;&#039;&#039; is a utility that lets you view the system security audit log.  =Criteria for Selecting Records= /SELECT specifies the criteria for selecting records for t...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.vmssoftware.com/index.php?title=ANALYZE/AUDIT&amp;diff=398&amp;oldid=prev"/>
		<updated>2019-03-28T12:42:19Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;ANALYZE/AUDIT&amp;#039;&amp;#039;&amp;#039; is a utility that lets you view the system security audit log.  =Criteria for Selecting Records= /SELECT specifies the criteria for selecting records for t...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;ANALYZE/AUDIT&amp;#039;&amp;#039;&amp;#039; is a utility that lets you view the system security audit log.&lt;br /&gt;
&lt;br /&gt;
=Criteria for Selecting Records=&lt;br /&gt;
/SELECT specifies the criteria for selecting records for the audit report.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! colspan=&amp;#039;col&amp;#039; | Criterion&lt;br /&gt;
! colspan=&amp;#039;col&amp;#039; | Description&lt;br /&gt;
|-&lt;br /&gt;
| ACCESS&lt;br /&gt;
| Specifies the type of object access upon which the selection is based: ASSOCIATE, CONTROL, CREATE, DELETE, EXECUTE, LOCK, LOGICAL, MANAGE, PHYSICAL, READ, SUBMIT, USE, WRITE&lt;br /&gt;
|-&lt;br /&gt;
| ACCOUNT&lt;br /&gt;
| Specifies the account name on which the selection is based. Wildcards can be used&lt;br /&gt;
|-&lt;br /&gt;
| ASSOCIATION_NAME&lt;br /&gt;
| Specifies the name of the interprocess communication (IPC) association&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_NAME&lt;br /&gt;
| Specifies the audit journal name on which the selection is based.&lt;br /&gt;
|-&lt;br /&gt;
| COMMAND_LINE&lt;br /&gt;
| Specifies the command line that the user entered&lt;br /&gt;
|-&lt;br /&gt;
| CONNECTION_IDENTIFICATION&lt;br /&gt;
| Specifies the name for the interprocess communication (IPC) connection&lt;br /&gt;
|-&lt;br /&gt;
| DECNET_LINK_IDENTIFICATION&lt;br /&gt;
| Specifies the number of the DECnet logical link&lt;br /&gt;
|-&lt;br /&gt;
|  DECNET_OBJECT_NAME&lt;br /&gt;
| Specifies the name of the DECnet object&lt;br /&gt;
|-&lt;br /&gt;
| DECNET_OBJECT_NUMBER&lt;br /&gt;
| Specifies the number of the DECnet object&lt;br /&gt;
|-&lt;br /&gt;
| DEFAULT_USERNAME&lt;br /&gt;
| Specifies the default local user name for incoming network proxy&lt;br /&gt;
|-&lt;br /&gt;
| DEVICE_NAME&lt;br /&gt;
|  Specifies the name of a device in audit records that have a DEVICE_NAME packet. Note that this does not select the device name when it occurs in other packet types, such as in a file name or in the TARGET_DEVICE_NAME packet&lt;br /&gt;
|-&lt;br /&gt;
| DIRECTORY_ENTRY&lt;br /&gt;
| Specifies the directory entry associated with file system operation&lt;br /&gt;
|-&lt;br /&gt;
| DIRECTORY_NAME&lt;br /&gt;
| Specifies the name of the directory file.&lt;br /&gt;
|-&lt;br /&gt;
| DISMOUNT_FLAGS&lt;br /&gt;
| Identifies the names of the volume dismounting flags to be used in selecting records. Specify one or more of the following flag names: Abort, Cluster, Nounload, and Unit.&lt;br /&gt;
|-&lt;br /&gt;
| EVENT_CLUSTER_NAME&lt;br /&gt;
| Specifies the name of the event flag cluster.&lt;br /&gt;
|-&lt;br /&gt;
| FACILITY&lt;br /&gt;
|  Specifies that only events audited by the named facility be selected. Provide a name or a number but, in either case, the facility has to be defined through the logical AUDSERV$FACILITY_NAME as a decimal number; the system uses the number 0.&lt;br /&gt;
|-&lt;br /&gt;
| FIELD_NAME&lt;br /&gt;
| Specifies the name of the field that was modified. ANALYZE/AUDIT uses the FIELD_NAME criterion with packets containing the original data and the new data (specified by the NEW_DATA criterion). A FIELD_NAME is a character string that describes the content of the field. A search for &amp;quot;NEW:&amp;quot; in a full audit report will display records that contain the FIELD_NAME values that can be specified for this option. Examples of FIELD_NAME values are Account, Default Directory, Flags, and Password Date. For sensitive information, see SENSITIVE_FIELD_NAME.&lt;br /&gt;
|-&lt;br /&gt;
| FILE_NAME&lt;br /&gt;
| Describes audit records for the specified file by using a slightly different display format than is provided by the /OBJECT=NAME=object-name keyword.&lt;br /&gt;
|-&lt;br /&gt;
| FILE_IDENTIFICATION&lt;br /&gt;
| Specifies the value of the file&amp;#039;s identification. To calculate the value, start with the value listed for File ID when you use  the FILE_NAME keyword. For example, the display lists the File ID&lt;br /&gt;
as (3024,5,0), use the following formula to calculate the value: (((0 * 65536) + 5)* 65536) + 3024 = 330704&lt;br /&gt;
|-&lt;br /&gt;
| FLAGS&lt;br /&gt;
|  Identifies the names of the audit event flags associated with the audited event. These names should be used in selecting records. Specify one or more of the following flags: ACL, Alarm, Audit, Flush, Foreign, Internal, and Mandatory.&lt;br /&gt;
|-&lt;br /&gt;
| HOLDER&lt;br /&gt;
| Specifies the name of the holder. Wildcards can be used.&lt;br /&gt;
|-&lt;br /&gt;
| IDENTIFIER&lt;br /&gt;
| Identifies which attributes of an identifier should be used when selecting event records. The following keywords can be used: ATTRIBUTES, NAME, NEW_NAME, NEW_ATTRIBUTES, VALUE, NEW_VALUE&lt;br /&gt;
|-&lt;br /&gt;
| IDENTIFIERS_MISSING&lt;br /&gt;
| Specifies the identifiers missing in a failure to access an object.&lt;br /&gt;
|-&lt;br /&gt;
| IDENTIFIERS_USED&lt;br /&gt;
|  Specifies the identifiers used to gain access to an object. An event record matches if the specified list is a subset of the identifiers recorded in the event record&lt;br /&gt;
|-&lt;br /&gt;
| IMAGE_NAME&lt;br /&gt;
| Identifies the name of the image to be used when selecting event records. You can represent all or part of the image name with a wildcard&lt;br /&gt;
|-&lt;br /&gt;
| INSTALL&lt;br /&gt;
| Specifies that installation event packets are to be considered when selecting event records. Choose from the following keywords: FILE, FLAGS, PRIVILEGES&lt;br /&gt;
|-&lt;br /&gt;
| LNM_PARENT_NAME&lt;br /&gt;
| Specifies the name of the parent logical name table&lt;br /&gt;
|-&lt;br /&gt;
| LNM_TABLE_NAME&lt;br /&gt;
| Specifies the name of the logical name table&lt;br /&gt;
|-&lt;br /&gt;
| LOCAL&lt;br /&gt;
| Specifies the characteristics of the local (proxy) account to be used when selecting event records. The following characteristic is supported: USERNAME&lt;br /&gt;
|-&lt;br /&gt;
| LOGICAL_NAME&lt;br /&gt;
| Specifies the logical name of the mounted (or dismounted) volume upon which selection is based. You can represent all or part of the logical name with a wildcard.&lt;br /&gt;
|-&lt;br /&gt;
| MAILBOX_UNIT&lt;br /&gt;
| Specifies the number of the mailbox unit.&lt;br /&gt;
|-&lt;br /&gt;
| MOUNT_FLAGS&lt;br /&gt;
|  Specifies the names of the volume mounting flags upon which selection is based. Possible flag names include the following names: CACHE=(NONE,WRITETHROUGH), CDROM, CLUSTER, COMPACTION, DATACHECK=(READ,WRITE),  DSI, FOREIGN, GROUP, INCLUDE, INITIALIZATION=(ALLOCATE,CONTINUATION), MESSAGE, NOASSIST, NOAUTOMATIC, NOCOMPACTION, NOCOPY, NOHDR3, NOJOURNAL, NOLABEL, NOMOUNT_VERIFICATION, NOQUOTA, NOREBUILD, NOUNLOAD, NOWRITE, OVERRIDE, POOL, QUOTA, SHARE, SUBSYSTEM, SYSTEM, TAPE_DATA_WRITE, XAR&lt;br /&gt;
|-&lt;br /&gt;
| NEW_DATA&lt;br /&gt;
| Specifies the value to use after the event occurs. Use this criterion with the FIELD_NAME criterion. When you use the Authorize utility (AUTHORIZE) to copy a user name, NEW_DATA specifies the newly created user name. For sensitive information, see SENSITIVE_NEW_DATA.&lt;br /&gt;
|-&lt;br /&gt;
| NEW_IMAGE_NAME&lt;br /&gt;
| Specifies the name of the image to be activated in the newly created process, as supplied to the $CREPRC system service.&lt;br /&gt;
|-&lt;br /&gt;
| NEW_OWNER&lt;br /&gt;
|  Specifies the user identification code (UIC) to be assigned to the created process, as supplied to the $CREPRC system service.&lt;br /&gt;
|-&lt;br /&gt;
| OBJECT&lt;br /&gt;
| Specifies which characteristics of an object should be used when selecting event records. Choose any of the following keywords: [[Object Class|CLASS]], NAME, TYPE, &lt;br /&gt;
|-&lt;br /&gt;
| PARENT&lt;br /&gt;
| Specifies which characteristics of the parent process are used when selecting event records generated by a subprocess. Choose from the following keywords:IDENTIFICATION,NAME,OWNER,USERNAME&lt;br /&gt;
|-&lt;br /&gt;
| PASSWORD&lt;br /&gt;
|  Specifies the password used when the system detected a break-in attempt.&lt;br /&gt;
|-&lt;br /&gt;
| PRIVILEGES_MISSING&lt;br /&gt;
| Specifies [[Privileges|privileges]] the caller needed to perform the operation successfully.&lt;br /&gt;
|-&lt;br /&gt;
| PRIVILEGES_USED&lt;br /&gt;
| Specifies the [[Privileges|privileges]] of the process to be used when selecting event records. Also include the STATUS keyword in the selection criteria so the report can demonstrate whether the privilege was involved in a successful or an unsuccessful operation.&lt;br /&gt;
|-&lt;br /&gt;
| PROCESS&lt;br /&gt;
|  Specifies the characteristics of the process to be used when selecting event records. Choose from the following characteristics: IDENTIFICATION, NAME&lt;br /&gt;
|-&lt;br /&gt;
| REMOTE&lt;br /&gt;
|  Specifies that some characteristic of the network request is to be used when selecting event records. Choose from the following keywords: ASSOCIATION_NAME, LINK_IDENTIFICATION, IDENTIFICATION, NODENAME, USERNAME&lt;br /&gt;
|-&lt;br /&gt;
| REQUEST_NUMBER&lt;br /&gt;
|  Specifies the request number associated with the DCL command REQUEST/REPLY.&lt;br /&gt;
|-&lt;br /&gt;
| SECTION_NAME&lt;br /&gt;
| Specifies the name of the [[Global Section|global section]]&lt;br /&gt;
|-&lt;br /&gt;
| SENSITIVE_FIELD_NAME&lt;br /&gt;
| Specifies the name of the field that was modified. ANALYZE/AUDIT uses the SENSITIVE_FIELD_NAME criterion, such as PASSWORD, with packets containing the original data and the new data (specified  by the SENSITIVE_NEW_DATA criterion).&lt;br /&gt;
|-&lt;br /&gt;
| SENSITIVE_NEW_DATA&lt;br /&gt;
| Specifies the value to use after the event occurs. Use this criterion with the SENSITIVE_FIELD_NAME criterion.&lt;br /&gt;
|-&lt;br /&gt;
| SNAPSHOT_BOOTFILE&lt;br /&gt;
| Specifies the name of the file containing a snapshot of the system.&lt;br /&gt;
|-&lt;br /&gt;
| SNAPSHOT_SAVE_FILENAME&lt;br /&gt;
|  Specifies the name of the system snapshot file for a save operation that is in progress.&lt;br /&gt;
|-&lt;br /&gt;
| STATUS&lt;br /&gt;
| Specifies the type of success status to be used when selecting event records. Choose from the following status types: SUCCESSFUL, FAILURE, CODE (completion status). Note that if you specify CODE more than once, only the last value is matched.&lt;br /&gt;
|-&lt;br /&gt;
| SUBJECT_OWNER&lt;br /&gt;
| Specifies the owner (UIC) of the process causing the event.&lt;br /&gt;
|-&lt;br /&gt;
| SUBTYPE&lt;br /&gt;
| Specifies that the criteria be limited to the value or values specified as a subtype. The following table lists events and their related subtypes. After SUBTYPE, enter the subtypes as they appear in the list-for example, SUBTYPE=ALARM_STATE. (In other words, do not enter a prefix.)&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! colspan=&amp;#039;col&amp;#039; | Event Type or Subtype&lt;br /&gt;
! colspan=&amp;#039;col&amp;#039; | Meaning&lt;br /&gt;
|-&lt;br /&gt;
| ALARM_STATE&lt;br /&gt;
| Events enabled as alarms&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_DISABLED&lt;br /&gt;
| Audit events disabled&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_ENABLED&lt;br /&gt;
| Audit events enabled&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_INITIATE&lt;br /&gt;
| Audit server startup&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_LOG_FIRST&lt;br /&gt;
| First entry in audit log (backward link)&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_LOG_FINAL&lt;br /&gt;
| Final entry in audit log (forward link)&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_STATE&lt;br /&gt;
| Events enabled as audits&lt;br /&gt;
|-&lt;br /&gt;
| AUDIT_TERMINATE&lt;br /&gt;
| Audit server shutdown&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_BREAKIN&lt;br /&gt;
| Break-in attempt detected&lt;br /&gt;
|-&lt;br /&gt;
| BATCH&lt;br /&gt;
| Batch process&lt;br /&gt;
|-&lt;br /&gt;
| DETACHED&lt;br /&gt;
| Detached process&lt;br /&gt;
|-&lt;br /&gt;
| DIALUP&lt;br /&gt;
| Dialup interactive process&lt;br /&gt;
|-&lt;br /&gt;
| LOCAL&lt;br /&gt;
| Local interactive process&lt;br /&gt;
|-&lt;br /&gt;
| NETWORK&lt;br /&gt;
| Network server task&lt;br /&gt;
|-&lt;br /&gt;
| REMOTE&lt;br /&gt;
| Interactive process from another network node&lt;br /&gt;
|-&lt;br /&gt;
| SUBPROCESS&lt;br /&gt;
| Subprocess&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_CONNECTION&lt;br /&gt;
| Logical link connection or termination&lt;br /&gt;
|-&lt;br /&gt;
| CNX_ABORT&lt;br /&gt;
| Connection aborted&lt;br /&gt;
|-&lt;br /&gt;
| CNX_ACCEPT&lt;br /&gt;
| Connection accepted&lt;br /&gt;
|-&lt;br /&gt;
| CNX_DECNET_CREATE&lt;br /&gt;
| DECnet logical link created&lt;br /&gt;
|-&lt;br /&gt;
| CNX_DECNET_DELETE&lt;br /&gt;
| DECnet logical link disconnected&lt;br /&gt;
|-&lt;br /&gt;
| CNX_DISCONNECT&lt;br /&gt;
| Connection disconnected&lt;br /&gt;
|-&lt;br /&gt;
| CNX_INC_ABORT&lt;br /&gt;
| Incoming connection request aborted&lt;br /&gt;
|-&lt;br /&gt;
| CNX_INC_ACCEPT&lt;br /&gt;
| Incoming connection request accepted&lt;br /&gt;
|-&lt;br /&gt;
| CNX_INC_DISCONNECT&lt;br /&gt;
| Incoming connection disconnected&lt;br /&gt;
|-&lt;br /&gt;
| CNX_INC_REJECT&lt;br /&gt;
| Incoming connection request rejected&lt;br /&gt;
|-&lt;br /&gt;
| CNX_INC_REQUEST&lt;br /&gt;
| Incoming connection request&lt;br /&gt;
|-&lt;br /&gt;
| CNX_IPC_CLOSE&lt;br /&gt;
| Interprocess communication association closed&lt;br /&gt;
|-&lt;br /&gt;
| CNX_IPC_OPEN&lt;br /&gt;
| Interprocess communication association opened&lt;br /&gt;
|-&lt;br /&gt;
| CNX_REJECT&lt;br /&gt;
| Connection rejected&lt;br /&gt;
|-&lt;br /&gt;
| CNX_REQUEST&lt;br /&gt;
| Connection requested&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_INSTALL&lt;br /&gt;
| Use of the Install utility (INSTALL)&lt;br /&gt;
|-&lt;br /&gt;
| INSTALL_ADD&lt;br /&gt;
| Known image installed&lt;br /&gt;
|-&lt;br /&gt;
| INSTALL_REMOVE&lt;br /&gt;
| Known image deleted&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_LOGFAIL&lt;br /&gt;
| Login failure&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_LOGIN&lt;br /&gt;
| Successful login&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_LOGOUT&lt;br /&gt;
| Successful logout&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_MOUNT&lt;br /&gt;
| Volume mount or dismount&lt;br /&gt;
|-&lt;br /&gt;
| VOL_DISMOUNT&lt;br /&gt;
| Volume dismount&lt;br /&gt;
|-&lt;br /&gt;
| VOL_MOUNT&lt;br /&gt;
| Volume mount&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_NCP&lt;br /&gt;
| Modification to network configuration database&lt;br /&gt;
|-&lt;br /&gt;
| NCP_COMMAND&lt;br /&gt;
| Network Control Program (NCP) command issued&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_NETPROXY&lt;br /&gt;
| Modification to network proxy database&lt;br /&gt;
|-&lt;br /&gt;
| NETPROXY_ADD&lt;br /&gt;
| Record added to network proxy authorization file&lt;br /&gt;
|-&lt;br /&gt;
| NETPROXY_DELETE&lt;br /&gt;
| Record removed from network proxy authorization file&lt;br /&gt;
|-&lt;br /&gt;
| NETPROXY_MODIFY&lt;br /&gt;
| Record modi&lt;br /&gt;
fied in network proxy authorization file&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_OBJ_ACCESS&lt;br /&gt;
| Object access attempted&lt;br /&gt;
|-&lt;br /&gt;
| OBJ_ACCESS&lt;br /&gt;
| Access attempted to create, delete, or deaccess an object&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_OBJ_CREATE&lt;br /&gt;
| Object creation attempted&lt;br /&gt;
|-&lt;br /&gt;
| OBJ_CREATE&lt;br /&gt;
| Access attempted to create an object&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_OBJ_DEACCESS&lt;br /&gt;
| Object deaccessed&lt;br /&gt;
|-&lt;br /&gt;
| OBJ_DEACCESS&lt;br /&gt;
| Attempt to complete access to an object&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_OBJ_DELETE&lt;br /&gt;
| Object deletion attempted&lt;br /&gt;
|-&lt;br /&gt;
| OBJ_DELETE&lt;br /&gt;
| Object deletion attempted&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_PROCESS&lt;br /&gt;
| Process controlled through a system service&lt;br /&gt;
|-&lt;br /&gt;
| PRC_CANWAK&lt;br /&gt;
| Process wakeup canceled&lt;br /&gt;
|-&lt;br /&gt;
| PRC_CREPRC&lt;br /&gt;
| Process created&lt;br /&gt;
|-&lt;br /&gt;
| PRC_DELPRC&lt;br /&gt;
| Process deleted&lt;br /&gt;
|-&lt;br /&gt;
| PRC_FORCEX&lt;br /&gt;
| Process exit forced&lt;br /&gt;
|-&lt;br /&gt;
| PRC_GETJPI&lt;br /&gt;
| Process information gathered&lt;br /&gt;
|-&lt;br /&gt;
| PRC_GRANTID&lt;br /&gt;
| Process identifier granted&lt;br /&gt;
|-&lt;br /&gt;
| PRC_RESUME&lt;br /&gt;
| Process resumed&lt;br /&gt;
|-&lt;br /&gt;
| PRC_REVOKID&lt;br /&gt;
| Process identifier revoked&lt;br /&gt;
|-&lt;br /&gt;
| PRC_SCHDWK&lt;br /&gt;
| Process wakeup scheduled&lt;br /&gt;
|-&lt;br /&gt;
| PRC_SETPRI&lt;br /&gt;
| Process priority altered&lt;br /&gt;
|-&lt;br /&gt;
| PRC_SIGPRC&lt;br /&gt;
| Process exception issued&lt;br /&gt;
|-&lt;br /&gt;
| PRC_SUSPND&lt;br /&gt;
| Process suspended&lt;br /&gt;
|-&lt;br /&gt;
| PRC_TERM&lt;br /&gt;
| Process termination notification requested&lt;br /&gt;
|-&lt;br /&gt;
| PRC_WAKE&lt;br /&gt;
| Process wakeup issued&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_PRVAUD&lt;br /&gt;
| Use of privilege&lt;br /&gt;
|-&lt;br /&gt;
| PRVAUD_FAILURE&lt;br /&gt;
| Unsuccessful use of privilege&lt;br /&gt;
|-&lt;br /&gt;
| PRVAUD_SUCCESS&lt;br /&gt;
| Successful use of privilege&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_RIGHTSDB&lt;br /&gt;
| Modification to the rights database&lt;br /&gt;
|-&lt;br /&gt;
| RDB_ADD_ID&lt;br /&gt;
| Identifier added to rights database&lt;br /&gt;
|-&lt;br /&gt;
| RDB_CREATE&lt;br /&gt;
| Rights database created&lt;br /&gt;
|-&lt;br /&gt;
| RDB_GRANT_ID&lt;br /&gt;
| Identifier granted to user&lt;br /&gt;
|-&lt;br /&gt;
| RDB_MOD_HOLDER&lt;br /&gt;
| List of identifier holders modified&lt;br /&gt;
|-&lt;br /&gt;
| RDB_MOD_ID&lt;br /&gt;
| Identifier name or attributes modified&lt;br /&gt;
|-&lt;br /&gt;
| RDB_REM_ID&lt;br /&gt;
| Identifier removed from rights database&lt;br /&gt;
|-&lt;br /&gt;
| RDB_REVOKE_ID&lt;br /&gt;
| Identifier taken away from user&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_SYSGEN&lt;br /&gt;
| Use of the [[SYSGEN|System Generation utility]]&lt;br /&gt;
|-&lt;br /&gt;
| SYSGEN_SET&lt;br /&gt;
| System parameter modified&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_SYSTIME&lt;br /&gt;
| Modification to system time&lt;br /&gt;
|-&lt;br /&gt;
| SYSTIM_SET&lt;br /&gt;
| System time set&lt;br /&gt;
|-&lt;br /&gt;
| SYSTIM_CAL&lt;br /&gt;
| System time calibrated&lt;br /&gt;
|-&lt;br /&gt;
| NSA$C_MSG_SYSUAF&lt;br /&gt;
| Modification to system user authorization file (SYSUAF)&lt;br /&gt;
|-&lt;br /&gt;
| SYSUAF_ADD&lt;br /&gt;
| Record added to system user authorization file&lt;br /&gt;
|-&lt;br /&gt;
| SYSUAF_COPY&lt;br /&gt;
| Record added to system user authorization file&lt;br /&gt;
|-&lt;br /&gt;
| SYSUAF_DELETE&lt;br /&gt;
| Record deleted from system user authorization file&lt;br /&gt;
|-&lt;br /&gt;
| SYSUAF_MODIFY&lt;br /&gt;
| Record modified in system user authorization file&lt;br /&gt;
|-&lt;br /&gt;
| SYSUAF_RENAME&lt;br /&gt;
| Record renamed in system user authorization file&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| SYSTEM&lt;br /&gt;
| Specifies the characteristics of the system to be used when selecting event records. Choose from the following keywords: IDENTIFICATION,NAME&lt;br /&gt;
|-&lt;br /&gt;
| SYSTEM_SERVICE_NAME&lt;br /&gt;
| Specifies the name of the system service associated with the event.&lt;br /&gt;
|-&lt;br /&gt;
| TARGET_DEVICE_NAME&lt;br /&gt;
| Specifies the target device name used by a process control system service.&lt;br /&gt;
|-&lt;br /&gt;
| TARGET_PROCESS_IDENTIFICATION&lt;br /&gt;
| Specifies the target process identifier (PID) used by a process control system service.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Darya.zelenina</name></author>
	</entry>
</feed>