IBM Support

IT36809: AUDIT LOG CONTAINS ONLY 3 DAYS OF INFORMATION ON A LARGE SYSTEM

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Due to the number of audit log entries captured, older
    entries are lost before reaching the configured retention time.
    
    Audit log entries in IBM Spectrum Protect Plus are rotated
    (i.e., removed because the maximum number of entries have been
    reached) before the configured retention time is reached due to
    the number of entries that are added to the audit log during
    normal operation. This issue is accelerated in a scaled
    environment due to the increased number of operations performed.
    For example, if the maximum number of entries is 500,000 and the
    configured retention time is 30 days, the audit log reaches
    500,000 entries in 3 days (long before the 30-day retention
    time). Ideally, the 500,000 entry maximum should not be reached
    before the oldest entry is 31 days old or older (i.e., rotation
    is performed by retention date rather than maximum count).
    
    This issue affects IBM Spectrum Protect Plus 10.1.7.ifix2 and
    10.1.8.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect Plus level 10.1.7 ifix2 and 10.1.8.     *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description.                                       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply the fixing level when available. This problem is       *
    * projected to be fixed in IBM Spectrum Protect Plus level     *
    * 10.1.8 patch1 and 10.1.9. Note that this is subject to       *
    * change at the discretion of IBM.                             *
    ****************************************************************
    

Problem conclusion

  • The number of entries added to the audit log have been reduced
    by removing retrieval operations from the audit log. Now only
    operations that modify or remove data (i.e. creation,
    modification, and deletion), as well as errors (even while
    retrieving data), are logged to the audit log. This dramatically
    reduces the number of entries added to audit log over time, and
    thus, reduces the rate at which the maximum number of audit log
    entries is reached.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT36809

  • Reported component name

    SP PLUS

  • Reported component ID

    5737SPLUS

  • Reported release

    A17

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-05-06

  • Closed date

    2021-06-09

  • Last modified date

    2021-06-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SP PLUS

  • Fixed component ID

    5737SPLUS

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSNQFQ","label":"IBM Spectrum Protect Plus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A17","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
31 January 2024