IBM Support

Guardium FAM: User Identification for File Operations

Question & Answer


Question

What user should I use to correctly identify file operations that are monitored with FAM (File Access Monitor)?

Cause

User activity is seen monitored under a few operating system (OS) users but the users may not have performed the activity.  It is also seen under Application Users.  

Answer

Use the Application User Name, not the OS User. The OS user could correspond to the user for an initial session request or could possibly be empty. For File Access Monitoring, use the Application User Name for file activity.  

To report on activity, use the Access Domain, SQL Entity and include the Application User Name.  

[{"Type":"MASTER","Line of Business":{"code":"","label":""},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCLRQQ","label":"Guardium for Files"},"ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
06 December 2023

UID

ibm17091348