如何审计IBM i NetServer网络共享的变更?
Great question—this is actually a common gap folks run into with IBM i's native auditing, since network share changes aren't explicitly called out in the standard QAUDJRN documentation. Let's break down some actionable ways to track these changes:
Audit the underlying system objects for share configurations
Network shares (like SMB or NFS) on IBM i depend on system objects to store their definitions. For SMB shares, the core configuration lives inQUSRSYS/QSMBSHR—a physical file that holds all share settings. You can enable object-level auditing for this file by runningEDTOBJAUD OBJ(QUSRSYS/QSMBSHR)and setting theObject auditattribute to*CHANGEor*ALL. Any create, edit, or delete action on shares will now trigger QAUDJRN entries for writes/updates to this file.Track share management commands via command auditing
All SMB share operations use specific commands:CRTSMBSHR(create),CHGSMBSHR(modify),DLTSMBSHR(delete). For NFS shares, you’ll work withCRTNFSNFSE,CHGNFSNFSE,DLTNFSNFSE. First, make sure your system’sQAUDCTLsystem value includes*CMDto enable command execution auditing. You can then filter QAUDJRN entries for these specific commands usingDSPJRN JRN(QAUDJRN) CMD(CRTSMBSHR CHGSMBSHR DLTSMBSHR)(adjust for NFS commands as needed), or parse logs programmatically using APIs likeQjoRetrieveJournalEntries.Leverage exit points for real-time monitoring
IBM i offers exit points that fire when share operations occur. For SMB shares, look for exit points related to share changes (check the IBM i Exit Point Registry for exact names, like those under the SMB service category). You can register a custom program to these exit points—this program will receive details about the change (user ID, action type, share name) and can log this info to a custom audit file, send alerts, or integrate with your existing security tools.Pull details from the system history log (QHST)
Most share configuration actions generate specific messages in theQHSTlog. For example:- Creating an SMB share triggers message
CPI3621("Shared resource &1 created") - Modifying a share triggers
CPI3622 - Deleting a share triggers
CPI3623
You can useDSPLOG MSGID(CPI3621 CPI3622 CPI3623)to filter these messages, or use theQMHRCVPMAPI to programmatically retrieve and log them for long-term tracking.
- Creating an SMB share triggers message
Use third-party security tools (if available)
If your organization uses tools like IBM Security Guardium for IBM i, these solutions often include pre-built rules for auditing network share changes. They abstract the need to build custom audit logic from scratch and can centralize logs across your IBM i environment.
内容的提问来源于stack exchange,提问作者MandyShaw

