Creating a Data Set of Outgoing Activity by IP Address with the Rule Wizard

To create a data set for examining activity and developing rules for outgoing activity based on IP address, select 51. Create Working Data Set from the Work with Dynamic Filtering screen (STRFW > 2).

The Summarize Outgoing IP Address (CPROIPSEC) screen appears. From this screen, you can construct the command line command that creates the data set.

    ​        ​   ​       ​   Summarize Outgoing IP Address (CPROIPSEC) ​                   
 ​
  ​        ​   ​                                                                     
 Type choices, press Enter.​                                                      
                                                                                
 Allowed  . . . . . . . . . . . .​   ​  *ALL          ​  *YES, *NO, *ALL               
 Starting date and time:         ​   ​               ​                                
   Starting date  . . . . . . . .​   ​  *CURRENT      ​  Date, *CURRENT, *YESTERDAY... 
   Starting time  . . . . . . . .​   ​  000000        ​  Time                          
 Ending date and time:           ​   ​               ​                                
   Ending date  . . . . . . . . .​   ​  *CURRENT      ​  Date, *CURRENT, *YESTERDAY... 
   Ending time  . . . . . . . . .​   ​  235959        ​  Time                          
 Number of records to process . .​   ​  *NOMAX          Number, *NOMAX                
 Set to contain data:            ​   ​               ​                                
   Set name . . . . . . . . . . .​   ​  *TEMP         ​  Name, *USER, *SELECT, *S...   
   Replace or add records . . . .​   ​  *ADD          ​  *ADD, *REPLACE                
 Wizard type  . . . . . . . . . .​   ​  *FAST         ​  *STD, *FAST, *NO              
                                                                                
                                                                                
                                                                                
                                                                                
                                                                 ​
        Bottom​  
 F3=Exit   F4=Prompt   F5=Refresh   F12=Cancel   F13=How to use this display    
 F24=More keys                                                                 ​
 
                                                                                

The screen contains the following fields. Fields that have values other than the defaults are preceded by the ">" character:

Allowed

Specifies whether the data set includes rejected activity, accepted activity, or both.

  • *YES: Include only accepted activity
  • *NO: Include only rejected activity
  • *ALL: Include both accepted and rejected activity

Starting date and time

Starting date

The day or date on which the included data begins.

Allowed values include:

  • *CURRENT: The current date
  • *YESTERDAY: Yesterday's date
  • *WEEKSTR: The first day of the current week. By default, this is Sunday.
  • *PRVWEEKS: The first day of the previous week
  • *MONTHSTR: The first day of the current month
  • *PRVMONTHS: The first day of the previous month
  • *YEARSTR: The first day of the current year
  • *PRVYEARS: The first day of the previous year
  • *MON: Monday
  • *TUE: Tuesday
  • *WED: Wednesday
  • *THU: Thursday
  • *FRI: Friday
  • *SAT: Saturday
  • *SUN: Sunday

Starting time

The time on the Starting date at which the included data begins, in HHMMSS format.

Ending date

The day or date on which the included data ends.

Allowed values are the same as for Starting date.

Ending time

The time on the Starting date at which the included data ends, in HHMMSS format.

Number of records to process

Collect no more than this number of records. If set to *NOMAX, collect all the relevant records.

Server ID

The server that the activity is attempting to access. To see a list of possible values, press the F4 key.

Set to contain data

Set name

The name of the data set that will contain the records. You can set this to your own value or choose one of these options:

  • *TEMP: The default name for temporary data sets. The data set is removed when the session ends.
  • *USER: Your user name
  • *S: Equivalent to *SELECT
  • *SELECT: If the wizard has been run before, a list appears of previous names that had been used for the data set.

Replace or add records

If any records already exist in the data set, whether to replace them or add the new records to them.

Possible values include:

  • *ADD: Add new records to the existing set
  • *REPLACE: Replace all existing records with the new ones.

Wizard type

The type of wizard to be created. Possible values include:

  • *STD: The Rule Wizard screen that appears next has all the standard options
  • *FAST: The Rule Wizard screen that appears next has a limited set of options for faster processing, as documented there.
  • *NO: The data set will only be used to batch processing.

To list and select possible values for many of the fields, place the cursor within the field and press the F4 key.

To reset the values on the screen to their default values, press the F5 key.