Auditing Directory Data Using the DSMAPINPUT FullSync Process

These topics provide an overview of the directory auditing processes and discuss how to audit directory data.

Page Name

Definition Name

Usage

Directory Audit Page

EO_RUNCTL_DS_AUDIT

Clean and load the temporary files. Also, load members into directory groups using entry membership rules and merge contents of multiple LDIF files into a single file.

Full Data Publish Page

EO_FULLDATAPUB

Set rules to publish the DSMAPINPUT_FULLSYNC_A service operation.

Monitor Overview Page

IB_MONITOR_OVRVIEW

Review the status of the DSMAPINPUT_FULLSYNC_A service operation.

Once you have loaded data into the directory and started processing transactions, you can regularly run the Directory Audit process or DSMAPINPUT FullSync Audit process to compare the data in the database to that in the directory.

Use the DSMAPINPUT FullSync Audit process to audit only people and their job data. Use the Directory Load process when you are auditing data that includes location and department entries in addition to person and job data.

Note: The Directory Audit process sometimes experiences performance issues when loading a auditing volume of person data. To avoid these issues, use the DSMAPINPUT FullSync Audit process.

Run the Clean Temp and Load from Dir (EODS_CLEANLD) process from the Directory Audit page.

  1. Specify the appropriate map name and click Run.

  2. Select the EODS_CLEANLD process from the list and click OK.

Note: Do not run the Directory Load (EO_DS_AUDIT) process.

Use the Full Data Publish page (EO_FULLDATAPUB) to set rules to publish the DSMAPINPUT_FULLSYNC_A service operation.

The DSMAPINPUT service operation combines information from a person's job and personal data into one service operation. The DSMAPINPUT_FULLSYNC_A is a FullSync service operation that is based on the DSMAPINPUT service operation structure and is defined within the DSMANCHNL service operation queue. The queue is partitioned on the emplID field to enable parallel processing. The Full Data Publish utility publishes the service operation. The subscription utility processes multiple streams of emplID data simultaneously. Each subscription produces a unique LDIF file containing LDAP commands for a range of people.

The utility processes the first active map it finds in the Directory Map table. If several maps contain DSMAPINPUT as the message name, ensure that you activate the service operation for only the message that you want before running this process.

  1. Access the Full Data Publish page.

  2. Select a Process Frequency of Once.

  3. In the Message Name field, enter DSMAPINPUT_FULLSYNC_A.

  4. Specify a Request ID and description, save your changes and click Run.

  5. Choose the Full Table Data Publish (EOP_PUBLISHT) process and click OK.

Note: You can choose to use your own service operation instead of DSMAPINPUT_FULLSYNC_A but you must add FULLSYNC_A to the name of the service operation from the directory map. For example, if PERSMSG is a configured service operation specified on the map for person entries, name the service operation PERSMSG_FULLSYNC_A.

Use the Monitor Overview page (IB_MONITOR_OVRVIEW) to review the status of the DSMAPINPUT_FULLSYNC_A service operation.

Monitor the service operation queue to determine the status of the DSMAPINPUT_FULLSYNC_A message within the DSMANCHNL service operation queue.

  1. Access the Monitor Overview page.

  2. If the Started column has a number greater than zero, it means the message is still being processed. When the subscriptions are completed, the only column that will have a number greater than zero is the Done column.

See PeopleTools: Integration Broker and PeopleTools: Integration Broker Administration.

Use the Directory Audit page (EO_RUNCTL_DS_AUDIT) to clean and load the temporary files. Also, load members into directory groups using entry membership rules and merge contents of multiple LDIF files into a single file.

After verifying on the Monitor Overview page that all service operation subscriptions are complete, run the Entry Membership and LDIF Merge (EODS_LDIFMRG) process to load members into directory groups based on the Entry Membership Rules and to merge the contents of all the LDIF files that were generated during the full table publish. You can review the merged file later, modify the contents, and import them into the directory later.

To run the Entry Membership and LDIF Merge process:

  1. Access the Directory Audit page.

  2. Specify the appropriate map and click Run.

  3. Choose the EODS_LDIFMRG process and click OK.

Note: Do not run the Clean Temp Tables or the Directory Load (EO_DS_AUDIT) process at this time.