IBM Support

Authority for Navigator for i Monitors

News


Abstract

For the new Navigator Access Authorization Options, see https://www.ibm.com/support/pages/node/6483569

Content

You are in: IBM i Technology Updates  > IBM Navigator for i > Monitors > Authority for Navigator for i Monitors

 
Monitor Authority
Topics:
For quick access to system monitors,  add the user profile to these authorization lists:
  • QNAVMNTR (new) or QINAVMNTR (heritage)
  • QPMCCFCN
  • QPMCCDATA - for viewing data

Monitor function access requirements

New Navigator Monitors uses QNAVMNTR and QPMCCFCN Authorization Lists:

If a user is in both QNAVMNTR and QPMCCFCN, they can perform all the available function with New Navigator System Monitors. 

New Navigator PDI uses and QPMCCDATA Authorization List:
QPMCCDATA is required to view the resulting collections with Performance Data Investigator (PDI)
Action
Description of action
New Navigator: With access through authorization lists
*ALLOBJ authority
View System & Message Monitors Monitors-> System or Message Yes with QNAVMNTR *USE
Visualize System Monitor Data "Dashboard" Display real-time monitor data with all metrics on dashboard (PDI) Yes with *USE in QPMCCDATA authority list Yes
Investigate System Monitor Data Display the selected single metric with PDI charts Yes with *USE in QPMCCDATA authority list Yes
Event Log Show the event log entries for this monitor Yes with QNAVMNTR *USE Yes

Start

Note: A new monitor needs to be started after creation

Start this system monitor (conditional)
Yes with QNAVMNTR *ALL
- system monitor also requires QPMCCFCN *USE
For proper trigger of monitors, user must be able to perform a CREATE or REPLACE ALIAS command and to visualize metrics with Performance Data Investigator (PDI)
Yes
Stop Stop this system monitor (conditional)
Yes with QNAVMNTR *ALL
- system monitor also requires QPMCCFCN *USE
Yes
New Based on Create a system monitor based on selected one Yes with QNAVMNTR *ALL Yes
Delete Delete this system monitor (available for "stopped" monitors) Yes with QNAVMNTR *ALL Yes
Properties - [Edit] Display or change the attributes of this monitor Yes with QNAVMNTR *ALL Yes
System Monitor ->Summary Yes with QNAVMNTR *USE
Monitor Server  Start or Stop N/A Yes

 
Heritage Navigator: for a monitor you do not own
Visualize Monitor Data Yes
Investigate Monitor Data Yes
Event Log Yes

Start

Note: A new monitor needs to be started after creation

NO
Stop NO
New Based on Yes
Delete NO
Properties Yes
Monitor Server  N/A


Authorization Lists
Monitor Data Queue
Access to the monitor data queue is provided through the QNAVMNTR authorization list
New Navigator Monitors - QNAVMNTR
Heritage Monitors - QINAVMNTR
The following functions can be performed by a user profile with either
  • *ALLOBJ special authority (for example, User Class *SECOFR authority with *ALLOBJ)
OR
  • Access through the specified authorization list

For correct access needed to run System or Message Monitors task in the IBM Navigator for i GUI, add a user profile to the authorization lists. 

Authorization List Description Start, stop, or delete monitor (*see ownership requirements above) To view the system monitor metrics graphs with Performance Data Investigator
QNAVMNTR - New
Access to the new monitor data queue Yes Not applicable
QINAVMNTR - Heritage Access to the heritage monitor data queue NO Not applicable
QPMCCFCN Access to the performance tools function Yes Yes
QPMCCDATA Access to the performance tools data Not applicable Yes
Summary:
  • With New Navigator only, it is allowed for a user profile to start, stop, or delete a monitor owned by another profile if they are included in both authorization lists
  • For information on the PDI authority requirements, see Authorization Requirements for PDI

Adding a User Profile

Adding a user profile to the authorization list can be done with the IBM Navigator for i GUI interface or through the green screen command line:

Navigator for i:

Authorization Lists

Figure 1: Open Authorization Lists under Security (or use search bar)

  • Filter on "QNAVMNTR" to find the lists
  • Select Permissions to view and edit the list.
  • Select Add to put in a new user profile.
  • Select Specify... and type in user profile, or select from list.
  • Select Ok or Apply to complete add

Green Screen Commands:

Use the EDTAUTL command on IBM i:

  1. EDTAUTL AUTL(QNAVMNTR)  
    • QINAVMNTR for heritage version
  2. Click F6 for Add new user
  3. <usrprf> *ALL

For one-line command use:
ADDAUTLE AUTL(QNAVMNTR) USER(<usrprf>) AUT(*ALL)


[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"Component":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB57","label":"Power"}}]

Document Information

Modified date:
02 January 2024

UID

ibm11164610