HP Systems Insight Manager 5.3 with Update 1 Installation and Configuration Guide for HP-UXHP Part Number: 418810-005 Published: April 2009 Edition: 5.3.1
enables the user to run the associated set of tools on that system or systems that are members of the system
group.
IMPORTANT: Authorization for a toolbox can enable users with non-privileged access (for example, non-root
users) to run tools as root or as another specified user. Be careful when granting users permission to run
tools as root. Consider all the capabilities given by a tool, above and beyond the capabilities it is designed
for, before you associate it with a toolbox.
CMS user configuration rights
In the central management server configuration rights section, select the level of authority to assign to the
new user from the following options. This is a required setting. If you selected an existing user or template
in the previous step, this information is already entered for you.
• full, allowed to modify all Central Management Server settings. Allows the user total control of the
database. Users can run discovery of systems and data collection; define users and authorizations; set
Cluster Monitor configuration; configure licensing and protocol settings; and create, modify, delete,
and run reports, snapshot comparisons, tools, custom tools, events, automation tasks, and so on.
• limited, allowed to create/modify/delete all reports and their own tools. Allows the user to create new
reports, edit any reports, and delete any reports (including the predefined reports).
• none, no configuration of Central Management Server allowed. Allows the user to view and run
predefined reports on the CMS and all managed systems. However, the user has no configuration rights
on the CMS or on the managed systems.
By default, root on an HP-UX CMS is assigned the administrative rights user privilege, but this permission
can later be revoked. This user is automatically authorized for the All Tools toolbox on all systems, including
the CMS. The
administrative rights user
privilege can be given to one or more users, and HP SIM requires
that at least one user is a administrative rights user.
Information storage
HP SIM uses an audit log and a database to track activity and store your management domain information.
On HP-UX the audit log is always located at: /var/opt/mx/logs/mx.log.
HP SIM audit log
HP SIM logs all tasks performed by all HP SIM users on all systems. The information is stored in the audit
log on the CMS. HP SIM logs all tasks with the following information:
• Time stamp
• User name
• Systems
• Event
• Tool result
For command tools, the verbose level of stdout and stderr is frequently large and time-sensitive, so it is
only logged by default for the ps command. You can configure the option to log this output for the ps and
other commands, as well as other aspects of the audit log, such as maximum file size. Information about
configuring the audit log is available in Chapter 12 “Configuration options” and in the "Administering the
Software" section of the
HP Systems Insight Manager 5.3 User Guide
at http://h18013.www1.hp.com/
products/servers/management/hpsim/infolibrary.html.
Database
HP SIM uses a database to store vital management domain information. The database contains the following
information:
• Authorizations
• Systems
• System lists
10 Product overview