IBM Support

What roles are assigned to predefined queries after Guardium patch install?

Question & Answer


Question

What is the behavior of the roles assigned to predefined queries after installing patches in Guardium? Will the roles I assign to queries be overwritten after patch install? What should I do if I dont want any users to see a predefined query?

Cause

Guardium GPU or combined fix pack (CFP) patches update existing, and may add new, predefined queries to the system. These actions can result in changes to the roles assigned to the queries. If roles were manually changed by the user, there may be a difference after installing GPU or CFP.

Other patches, for example sniffer or security patches, do not update existing reports and are less likely to add new ones.

Answer

The behavior of roles assigned to queries after GPU or CFP install is:

  • Customer defined queries will keep whatever roles were assigned to them.
  • Predefined queries with any defined role will keep that role
  • Predefined queries with no roles will be set back to 'all roles'
  • New predefined queries added in that patch have 'all roles' set

If there is a requirement for no users to be able to see a predefined query - Create a new role that has no users included, then assign that role to the query. This will ensure there is no change after patch install.

Related Information

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Guardium Appliances","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"10.0;10.0.1;10.1;10.1.2;9.0;9.1;9.5","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21996959