Help banner

Server Object Nsure Audit Settings - eDirectory

eDirectory events are partition-specific; that is, they only need to be enabled on one NCP Server object per partition. The eDirectory instrumentation can log events from eDirectory version 6 or higher.

The following table provides information on the eDirectory events and their associated threat risks.

IMPORTANT: In the case of a few critical events, eDirectory won’t complete a transaction until the corresponding event is sent to the Secure Logging Server. This ensures that the transaction is logged to the data store. These events are noted in the table.

NOTE: You do not need to restart the logging server to activate your changes in the eDirectory menu.

Label

Property Name

Description

Enabled by Default

Blocks eDirectory
until Logged

Meta

ACL Changed

 

 

 

 

 

Login Enabled

 

 

 

Login Disabled

 

 

 

 

Intruder Detected

 

 

 

 

Objects

Create

DSCreateEntry

A new eDirectory object has been created.

 

x

Delete

DSDeleteEntry

An existing eDirectory object has been deleted.

 

x

Rename

DSRenameEntry

An existing eDirectory object has been renamed.

 

x

Move (Source)

DSMoveSourceEntry

This event specifies the deletion of an eDirectory object from its original location in the Directory tree. (This is the second of two events reported for a move operation. The first is DSMoveDestEntry).

 

x

 

Move (Destination)

DSMoveDestEntry

This event specifies the placement of an eDirectory object into its new location in the Directory tree. (This is the first of two events reported for a move operation. The second is DSMoveSourceEntry.)This also generates DSAddValue
(-->DSAttribute) events for all of the values associated with the object.

 

x

 

Move (Subtree)

DSMoveSubtree

A container and its subordinate objects have been moved.

 

 

 

Backlink SEV

DSBKLinkSev

A backlink operation has updated an object's Security Equivalence Vector.

 

 

 

Backlink Operator

DSBKLinkOperator

A backlink operation has changed an object's console operator privileges.

 

 

 

Delete Subtree

DSDeleteSubtree

A container and its subordinate objects have been deleted.

 

 

x

Move Tree (Start)

DSMoveTreeStart

A Move Subtree operation has started.

 

 

 

Move Tree (End)

DSMoveTreeEnd

A Move Subtree operation has finished.

 

 

 

Name Collision

DSNameCollision

A name collision (two entries with the same name) has occurred.

 

 

x

DSA Read

DSDSARead

A Read operation has been performed on an entry.

 

 

 

Login

DSLogin

A user has logged in.

 

x

 

Change Password

DSChgPass

A user's password has changed.

 

x

 

Logout

DSLogout

A user has logged out.

 

x

 

Remove

DSRemoveEntry

An entry has been removed from a container.

 

x

 

Verify Password

DSVerifyPass

A password has been verified.

 

 

 

Backup

DSBackupEntry

An entry has been backed up.

 

 

 

Restore

DSRestoreEntry

An entry has been restored.

 

 

 

Remove Assoc.
Directory

DSRemoveEntryDir

A file directory associated with an entry has been removed.

 

 

 

DSStream

DSStream

A stream attribute has been opened or closed.

 

 

 

List Subordinates

DSListSubordinates

A List Subordinate Entries operation has been performed on a container object.

 

 

 

List Containable Classes

DSListContClasses

A List Containable Classes operation has been performed on an entry.

 

 

 

Mutate Entry

DSMutateEntry

A Mutate Entry operation has been performed on an entry.

 

x

 

Read Attribute

DSReadAttr

An entry's attributes have been read.

 

 

 

Read References

DSReadReferences

The references on a given object have been read.

 

 

 

Create Backlink

DSCreateBacklink

A backlink has been created.

 

 

 

Check Console Operator

DSCheckConsoleOperator

An object has been checked for Console Operator rights.

 

 

 

Add Property

DSAddProperty

An attribute (property) has been added to an object.

 

 

 

Delete Property

DSDeleteProperty

An attribute (property) has been removed from an object.

 

 

 

Add Group Member

DSAddMember

A member has been added to a Group object.

 

 

 

Delete Group
Member

DSDeleteMember

A member has been deleted from a Group object.

 

 

 

Read Object Info

DSReadObjInfo

A Read Object Info operation has been performed on an object.

 

 

 

Search

DSSearch

A Search operation has been performed.

 

 

 

Remove Backlink

DSRemoveBacklink

A backlink has been removed.

 

 

 

Change Security Equals

DSChangeSecurityEquals

An object's Security Equals attribute.

 

x

x

Add Entry

DSAddEntry

An entry has been added beneath a container.

 

 

 

Modify RDN

DSModifyRDN

A rename operation has been performed.

 

 

 

Allow Login

DSAllowLogin

A user has been allowed to log in.

 

 

 

Attributes

Add Value

DSAddValue

A value has been added to an object attribute.

 

x

Delete Value

DSDeleteValue

A value has been deleted from an object attribute.

 

x

Delete Attribute

DSDeleteAttribute

An attribute has been deleted from an object. This generates DSDeleteValue events for values associated with the attribute. The DSDeleteValue events occur after the DSDeleteAttribute event.

 

 

Compare Attribute Value

DSCompareAttrValue

A Compare operation has been performed on an attribute.

 

 

Modify Object

DSModifyEntry

An attribute has been modified on an object.

 

x

 

Schema

Update Class Definition

DSUpdateClassDef

A schema class definition has been updated.

 

x

Update Attribute Definition

DSUpdateAttrDef

A schema attribute definition has been updated.

 

x

Schema
Synchronized

DSSchemaSync

The schema has been synchronized.

 

Define Attribute

DSDefineAttrDef

An attribute definition has been added to the schema.

 

x

 

Remove Attribute

DSRemoveAttrDef

An attribute definition has been removed from the schema.

 

x

 

Remove Class

DSRemoveClassDef

A class definition has been removed from the schema.

 

x

 

Define Class

DSDefineClassDef

A class definition has been added to the schema.

 

x

 

Modify Class

DSModifyClassDef

A class definition has been modified.

 

x

 

Synchronized
Schema

DSSyncSchema

The schema has been synchronized.

 

 

 

Update Schema

DSUpdateSchema

An Update Schema operation has been performed.

 

 

 

Start Update
Schema

DSStartUpdateSchema

A Start Update Schema operation has been performed.

 

 

 

End Update Schema

DSEndUpdateSchema

An End Update Schema operation has been performed.

 

 

 

New Schema Epoch

DSNewSchemaEpoch

A new schema epoch has been declared.

 

x

 

Connections

Remote Server
Down

DSRemoteServerDown

A remote server has gone down.

 

x

NCP Retry Expended

DSNCPRetryExpended

The number of retries for an NCP™ request has been expended.

 

Remote Connection Cleared

DSRemoteConnCleared

A remote connection has been cleared.

 

x

 

Connected To
Address

DSConnectToAddress

A connection has been established with a particular address.

 

 

Agent

Module State
Changed

DSChangeModuleState

The eDirectory module's state has changed.

 

 

Local Agent Opened

DSAgentOpenLocal

The local Directory agent has been opened.

 

x

Local Agent Closed

DSAgentCloseLocal

The local Directory agent has been closed.

 

x

 

DSA Bad Verb

DSDSABadVerb

An incorrect verb number was given in a DSAgent request.

 

 

 

DSA Request Start

DSDSARequestStart

A DSAgent request has been started.

 

 

 

DSA Request End

DSDSARequestEnd

A DSAgent request has completed.

 

 

 

NLM Loaded

DSNLMLoaded

An NLM™ has been loaded.

 

 

 

DS Counters Reset

DSResetDSCounters

The internal eDirectory counters have been reset.

 

 

 

DS Reloaded

DSReloadDS

eDirectory has been reloaded.

 

x

 

Create Namebase

DSCreateNamebase

The Directory namebase has been created.

 

 

 

CRC Failure

DSCRCFailure

A CRC failure occurred when fragmented NCP requests were reconstructed.

 

 

 

Connection State Changed

DSChangeConnState

The connection state has changed.

 

 

 

End Namebase Transaction

DSEndNamebaseTransaction

An End Namebase Transaction debug message has been sent.

 

 

 

Miscellaneous

Close Stream

DSCloseStream

A Stream attribute has been closed.

 

 

Check SEV

DSCheckSEV

The Security Equivalence Vector has been checked.

 

 

Update SEV

DSUpdateSEV

The Security Equivalence Vector has been updated.

 

 

 

Delete Unused External Reference

DSDeleteUnusedExtRef

An unused external reference has been deleted.

 

 

 

Recertified Public
Key

DSRecertPubKey

An entry's public key has been certified.

 

 

x

Generated CA Keys

DSGenCAKeys

Certificate of Authority keys have been generated.

 

 

x

Bindery

Set Bindery Context

DSSetBinderyContext

The bindery context has been set on the server.

 

 

Create Bindery
Object

DSCreateBinderyObject

A bindery object has been created.

 

 

Delete Bindery
Object

DSDeleteBinderyObject

A bindery object has been deleted.

 

 

 

Error Via Bindery

DSErrViaBindery

An error was returned via the Bindery.

 

 

 

Change Property Security

DSChangePropSecurity

Security for a bindery object's property has been changed.

 

 

 

Change Object Security

DSChangeObjSecurity

A bindery object's security has been changed.

 

 

 

Open Bindery

DSOpenBindery

The Bindery has been opened.

 

 

 

Close Bindery

DSCloseBindery

The Bindery has been closed.

 

 

 

Replica

No Replica Pointer

DSNoReplicaPtr

A replica exists that has no replica pointer associated with it.

 

 

x

Inbound Sync End

DSSyncInEnd

Inbound synchronization has finished.

 

 

New Master Set

DSSetNewMaster

A new master replica has been designated.

 

 

 

Partition State
Change Request

DSPartStateChgReq

A partition state change has been requested.

 

 

 

Lost Entry

DSLostEntry

eDirectory has encountered a lost entry. A lost entry is an entry for which updates are being received, but no entry exists on the local server.

 

 

x

Purge Entry Failed

DSPurgeEntryFail

A purge operation on an entry has failed.

 

 

x

Purge Start

DSPurgeStart

A purge operation has started.

 

 

x

Purge End

DSPurgeEnd

A purge operation has ended.

 

 

 

FlatCleaner End

DSFlatCleanerEnd

A Flatcleaner operation has completed.

 

 

 

One Replica

DSOneReplica

A partition has been encountered that has only one replica. Novell® recommends that each partition have at least three replicas for greater fault-tolerance.

 

 

x

Limber Done

DSLimberDone

A Limber operation has completed.

 

 

 

Outbound Sync (Server) Start

DSSyncSvrOutStart

Outbound synchronization has begun from a particular server.

 

 

 

Outbound Sync (Server) End

DSSyncSvrOutEnd

Outbound synchronization from a particular server has finished.

 

 

 

Added Replica

DSAddReplica

A replica of a partition has been added to a server.

 

 

 

Removed Replica

DSRemoveReplica

A replica of a partition has been removed from a server.

 

 

 

Changed Replica
Type

DSChangeReplicaType

A partition replica's type has been changed.

 

 

 

Received Replica Updates

DSRecvReplicaUpdates

A replica has received an update during synchronization.

 

 

 

Repaired
Timestamps

DSRepairTimeStamps

A replica's time stamps have been repaired.

 

 

 

Sent Replica
Updates

DSSendReplicaUpdates

A replica has sent an update during synchronization.

 

 

 

Inspected Entry

DSInspectEntry

An Inspect Entry operation has been performed on an entry.

 

 

 

Resent Entry

DSResendEntry

A Resend Entry operation has been performed on an entry.

 

 

 

Merged Entries

DSMergeEntries

Two entries have been merged.

 

 

 

Updated Replica

DSUpdateReplica

An Update Replica operation has been performed on a partition replica.

 

 

 

Start Update Replica

DSStartUpdateReplica

A Start Update Replica operation has been performed on a partition replica.

 

 

 

End Update Replica

DSEndUpdateReplica

An End Update Replica operation has been performed on a partition replica.

 

 

 

EntryIDs Swapped

DSEntryIDSwap

A Swap Entry ID operation has been performed.

 

 

 

Partition

Referral Created

DSReferral

A referral has been created.

 

 

Split Done

DSSplitDone

A Split Partition operation has completed.

 

 

Sync Partition Start

DSSyncPartStart

Synchronization of a partition has begun.

 

 

x

Sync Partition End

DSSyncPartEnd

Synchronization of a partition has finished.

 

 

 

Join Done

DSJoinDone

A Join Partitions operation has completed.

 

 

x

Partition Locked

DSPartitionLocked

A partition has been locked.

 

 

 

Partition Unlocked

DSPartitionUnlocked

A partition has been unlocked.

 

 

 

Lumber Done

DSLumberDone

A Lumber operation has completed.

 

 

 

Backlink Procedure Done

DSBacklinkProcDone

A backlink process has completed.

 

 

 

Server Renamed

DSServerRename

A server has been renamed.

 

 

x

Synthetic Time
Issued

DSSyntheticTime

To bring eDirectory servers into synchronization, synthetic time has been invoked.

 

x

x

Server Address Changed

DSServerAddressChange

A server's address has changed.

 

 

 

Split Partition

DSSplitPartition

A partition has been split.

 

x

 

Join Partitions

DSJoinPartitions

A parent partition has been joined with a child partition.

 

x

 

Abort Partition Operation

DSAbortPartitionOp

A partition operation has been aborted.

 

 

 

Merge Trees

DSMergeTree

Two eDirectory trees have been merged.

 

x

 

Create Subref

DSCreateSubref

A subordinate reference has been created.

 

 

 

List Partitions

DSListPartitions

A List Partitions operation has been performed.

 

 

 

Sync Partition

DSSyncPartition

A Synchronize Partition operation has been performed on a partition replica.

 

 

 

Change Tree Name

DSChangeTreeName

The tree name has been changed.

 

x

 

Start Join

DSStartJoin

A Start Join operation has been performed.

 

x

 

Abort Join

DSAbortJoin

A Join operation has been aborted.

 

x

 

Move Tree

DSMoveTree

A Move Tree operation has been performed.

 

x

 

Partition State Changed

DSPartitionStateChg

A partition's state has changed.

 

x

 

Low Level Join

DSLowLevelJoin

A low-level join has been performed.

 

 

 

Orphaned Partition

DSOrphanPartition

An orphan partition operation has been performed. This operation has four variations: Create, Remove, Link, and Unlink.

 

 

 

Low Level Split

DSLowLevelSplit

A low-level partition split has been performed.

 

 

 

 

 

For information on file system events logged by Nsure Audit, see Filesystem Events.
For information on NetWare events logged by Nsure Audit, see NetWare Events.
For more information on using Nsure Audit, see Nsure Audit Help.

A trademark symbol (®, TM, etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party trademark. For information on trademarks, see Legal Notices.