<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Splunk input IBM SMF records? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162611#M98064</link>
    <description>&lt;P&gt;The following Splunk Blog outlines how Splunk and IBM are partnering to help customers integrate IBM Z (Mainframe) Data and Insights into Splunk software:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2017/08/22/insane-in-the-mainframe-splunk-and-ibm-partner-to-provide-end-to-end-visibility-for-joint-customers.html"&gt;https://www.splunk.com/blog/2017/08/22/insane-in-the-mainframe-splunk-and-ibm-partner-to-provide-end-to-end-visibility-for-joint-customers.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2017 16:39:06 GMT</pubDate>
    <dc:creator>tldenney</dc:creator>
    <dc:date>2017-09-20T16:39:06Z</dc:date>
    <item>
      <title>Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162602#M98055</link>
      <description>&lt;P&gt;Can IBM SMF records be input to Splunk from z/OS?  I am interested in indexing RACF data specifically.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162602#M98055</guid>
      <dc:creator>CZ1900Splunker</dc:creator>
      <dc:date>2013-12-02T17:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162603#M98056</link>
      <description>&lt;P&gt;Yes it can. But rather, the question is; can you get your mainframe to dump the SMF records in a readable format (i.e. not EBCDIC) and transport it to a place where the file can be indexed by Splunk?&lt;/P&gt;

&lt;P&gt;As you know, there is no forwarder for the mainframe platform (read z/OS), and 'syslog' is not necessarily part of the mainframe toolkit.&lt;/P&gt;

&lt;P&gt;I have seen this done with the help of some JCL-code to dump relevant SMF records as XML (yes, I know that it's huge) and transport it via (S)FTP on a regular basis to a place where Splunk reads it as a file. I believe that the conversion from EBCDIC to ASCII was performed by the mainframe FTP utility (in a fairly automated manner).&lt;/P&gt;

&lt;P&gt;Google your way to find sample code for dumping SMF records (offered on some IBM web sites), show it to your mainframe people and ask them to adapt it to their environment.&lt;/P&gt;

&lt;P&gt;Best of luck,&lt;/P&gt;

&lt;P&gt;/K &lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 21:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162603#M98056</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-12-02T21:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162604#M98057</link>
      <description>&lt;P&gt;Thanks Kristian.  There's no problem getting the data to the server.  But, does Splunk already know how SMF records are formatted or does something have to be done manually to index the data?  I did not see SMF listed as a data source type.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 12:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162604#M98057</guid>
      <dc:creator>CZ1900Splunker</dc:creator>
      <dc:date>2013-12-03T12:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162605#M98058</link>
      <description>&lt;P&gt;No. There is no pretrained sourcetype, if that is what you mean. But getting the output as XML will vastly simplify the parsing of the (variable length) SMF records, since the  XML tags are created by the mainframe, and are thus done so correctly. &lt;/P&gt;

&lt;P&gt;Then you will have to find out how the various XML-tagged fields will map to 'Failed Login' or 'Access Granted' etc.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 16:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162605#M98058</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-12-03T16:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162606#M98059</link>
      <description>&lt;P&gt;Ironstream from Syncsort can do all of this work for you.  It will handle all of the issues related to z/OS SMF records.  It deals with the compression, the triplets, the binary data and converts the data from EBCDIC to ASCII.  It does this very efficiently, even offloading a lot of the work to a zIIP engine in  order to keep the MSU cost of this work to an absolute minimum.  This is all done in real time to give you the best data latency possible while not impacting the existing workload on your system. &lt;/P&gt;

&lt;P&gt;If you have other data sources like SYSLOG, Log4j or flat files, Ironstream can handle those as well. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 19:47:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162606#M98059</guid>
      <dc:creator>jreda</dc:creator>
      <dc:date>2015-02-04T19:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162607#M98060</link>
      <description>&lt;P&gt;Here I am using IBM zSecure that is already installed on Mainframe and exporting via FTP to Splunk. So with the .txt file should do the parsing for regex.&lt;/P&gt;

&lt;P&gt;But Ironstream can do this more easily.&lt;BR /&gt;
&lt;A href="http://www.syncsort.com/en/Products/Mainframe/Ironstream"&gt;http://www.syncsort.com/en/Products/Mainframe/Ironstream&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 18:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162607#M98060</guid>
      <dc:creator>jfeitosa</dc:creator>
      <dc:date>2015-08-20T18:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162608#M98061</link>
      <description>&lt;P&gt;Hi how can I use ftp through splunk ? &lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 05:55:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162608#M98061</guid>
      <dc:creator>raymondleroux</dc:creator>
      <dc:date>2016-11-04T05:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162609#M98062</link>
      <description>&lt;P&gt;What data are you trying to get into Splunk? Do you mean FTP from a mainframe?&lt;/P&gt;

&lt;P&gt;I believe you would simply FTP the file to the Splunk indexer or even just a machine with a universal forwarder on it.  Then you can input the data from the file into Splunk through the manual interface via the browser or you can monitor the files in Splunk to upload when changes occur to that file.  &lt;/P&gt;

&lt;P&gt;More doc in data input from files here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/Monitorfilesanddirectories"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/Monitorfilesanddirectories&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you need real time log data from the mainframe, as mentioned above, Ironstream is a good solution that will take care of data mapping and transformation and get that data over in real-time to Splunk: &lt;/P&gt;

&lt;P&gt;&lt;A href="+http://www.syncsort.com/en/Products/Mainframe/Ironstream"&gt;http://www.syncsort.com/en/Products/Mainframe/Ironstream&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 12:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162609#M98062</guid>
      <dc:creator>jeastman</dc:creator>
      <dc:date>2016-11-04T12:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162610#M98063</link>
      <description>&lt;P&gt;&lt;A href="https://www.ibm.com/us-en/marketplace/common-data-provider-for-z-systems"&gt;IBM Common Data Provider for z Systems&lt;/A&gt; (CDPz) is the best option for sending SMF records to Splunk.&lt;/P&gt;

&lt;P&gt;CDPz can send a wide variety of data including 140 data sources and 100+ SMF record types. More specifically, CDPz can support the following:&lt;/P&gt;

&lt;P&gt;• SMF records&lt;BR /&gt;
• SYSLOG (IBM z/OS System Log and USS SyslogD)&lt;BR /&gt;
• JOBLOGs&lt;BR /&gt;
• Application logs (IBM CICS Transaction Server logs and IBM WebSphere Application Server logs)&lt;/P&gt;

&lt;P&gt;CDPz also has advanced filtering capabilities including RegEx and time filtering that can be set up using the built-in web configuration tool shown below.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/61iE1857101C563920B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;More information on IBM Common Data Provider for z Systems can be found directly on &lt;A href="https://splunkbase.splunk.com/app/3615/"&gt;Splunkbase&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 16:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162610#M98063</guid>
      <dc:creator>tldenney</dc:creator>
      <dc:date>2017-06-29T16:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162611#M98064</link>
      <description>&lt;P&gt;The following Splunk Blog outlines how Splunk and IBM are partnering to help customers integrate IBM Z (Mainframe) Data and Insights into Splunk software:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2017/08/22/insane-in-the-mainframe-splunk-and-ibm-partner-to-provide-end-to-end-visibility-for-joint-customers.html"&gt;https://www.splunk.com/blog/2017/08/22/insane-in-the-mainframe-splunk-and-ibm-partner-to-provide-end-to-end-visibility-for-joint-customers.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 16:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162611#M98064</guid>
      <dc:creator>tldenney</dc:creator>
      <dc:date>2017-09-20T16:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162612#M98065</link>
      <description>&lt;P&gt;A clever and free way is using a SORT EXIT calling EZASMI to send anything to any syslog server.&lt;BR /&gt;
Use it for console/syslog messages, RACF IRRADU00/IRRDBU00. The sort has the advantage that you can filter on anything.&lt;BR /&gt;
Why paying big money to the big corporations for simple programs? &lt;/P&gt;

&lt;P&gt;Easy to send jobs step information to Splunk etc.&lt;BR /&gt;
&amp;lt;1&amp;gt; JCT scanned      : MOBI                  USERID: IBMUSER  READER: 2018-07-10 07:23:56:22 JOBSTART: 07:25:17:83 SMFID: APEX&lt;BR /&gt;&lt;BR /&gt;
PAL$TCP4-10 JOBNAME:MAXP001C JOB04459 STEP:COMPLINK ASM      PGM:ASMA90   CODE: 0004&lt;BR /&gt;&lt;BR /&gt;
PAL$TCP4-10 JOBNAME:MAXP001C JOB04459 STEP:COMPLINK LKED     PGM:IEWL     CODE: 0000&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 12:02:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162612#M98065</guid>
      <dc:creator>racfra2</dc:creator>
      <dc:date>2018-07-10T12:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162613#M98066</link>
      <description>&lt;P&gt;If you are just interested in SYSLOG data only, Syncsort's Ironstream has a "starter edition" that is FREE and only sends SYSLOG data.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.syncsort.com/en/testdrive/ironstream-starter-edition"&gt;http://www.syncsort.com/en/testdrive/ironstream-starter-edition&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162613#M98066</guid>
      <dc:creator>jeastman</dc:creator>
      <dc:date>2018-07-10T13:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk input IBM SMF records?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162614#M98067</link>
      <description>&lt;P&gt;Many thanks for the info.  Interesting tool.  We have different needs to cover joblogs(job/Step termination within batch jobs), syslog,RACF, data from user exits ... data from any file etc. to b sent to any kind of syslog servers. In many cases using sort exits is the smartest way for us, as a user can filter the data as needed.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 16:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-input-IBM-SMF-records/m-p/162614#M98067</guid>
      <dc:creator>racfra2</dc:creator>
      <dc:date>2018-07-10T16:15:46Z</dc:date>
    </item>
  </channel>
</rss>

