Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Lost Data Audit Trail
System
TeamSite 5.5.2 on W2K.
I have a user that claims changes they made to a templated file before going on vacation in early August were lost. I can't find any record of those changes in the file history and I can't find anything about the files in iwevents.log during the period in question. There seem to be date gaps in the iwevent.log backup files (I don't administer the server, so I have asked for an explanation), and anyway, lack of evidence does not prove lack of activity (if the system lost her data, would it have logged it?). So I can't convince the user they never made the changes. I am wondering if there is any other place to look for a record of her activity. Any (combination) of the following seem entirely possible to me:
TeamSite actually lost the changes.
The user made the changes to the wrong DCR.
The user did not save the changes.
The user generated the wrong file.
The user did not submit their changes.
The changes were reverted by get latest or equivalent.
Somehow locking was defeated and another user edited the file at the same time.
The file has since been generated from a different DCR.
There could be a number of additional causes (there are so many ways the user can error in this system!) It seems to literally impossible to track the data and activity through the system using the events logs and file history - are there any other options?
Thanks,
-John
Find more posts tagged with
Comments
Adam Stoller
TeamSite actually lost the changes.
Unlikely
The user made the changes to the wrong DCR.
The user did not save the changes.
The user generated the wrong file.
The user did not submit their changes.
The changes were reverted by get latest or equivalent.
Unlikely. Even if the file were reverted, there would be an historical version of the submitted file that was reverted back to a previous state.
Somehow locking was defeated and another user edited the file at the same time.
Unlikely
The file has since been generated from a different DCR.
The most likely candidates are that the user is mistaken either with regard to having saved and submitted the changes, or with respect to which file(s) in which branch(es) they saved and submitted the changes.
If the modifications were never submitted then there is no way to really track it down.
If the modifications were submitted - you can use iwrlog to try and find the file in question - if need be you could run iwrlog over every single file in the workarea and grep through all the output looking for the user's name and associated date/comments/etc.
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
Migrateduser
Actually, having talked more with the user, I'm starting to think they did go through the edit process correctly and kicked off a workflow. I understand that the data could be lost if it was never submitted, but there should at least be lines in the event log showing that the file was locked to them when they chose to edit. These lines seem to be missing, or are associated with the wrong user and/or filename. Other edits made by this user in this date range do appear in the event log files.
Edited by john on 09/03/04 03:33 PM (server time).
Dwayne
Since you don't admin the box, is it possible that somebody did a restore from backup? That might explain the date gap as well as the missing data.
--
Current project: TS 5.5.2/6.1 W2K
Migrateduser
> is it possible that somebody did a restore from backup? That might explain the date gap as well as the missing data.
I got a more specific date window from the user. There was no backing store restoration done during that window, and it seems that the logs are "complete" (in the sense that the log entries in a single archived log file span the entire date range), but the specific edits in question are not logged while other edits the user performed during this window are logged.