Logging of Security-Related Events

This section describes MCP support for the logging of security-related events in the Sumlog.

You can use the LOGANALYZER RESULT option to filter analysis based on the assigned result.

RESULT Option

Description

SUCCESS

Successful actions that are not security relevant

FAILURE

Failed actions that are not related to security

RELEVANT

Successful actions that are security relevant

VIOLATION

Failed actions that are security relevant (security violations)

For example

  • LOG UC. RESULT RELEVANT selects successful security relevant records

  • LOG UC. RESULT VIOLATION selects security violations

  • LOG UC. RESULT RELEVANT VIOLATION selects all security relevant records (successful or not)