<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RACF Logs in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/RACF-Logs/m-p/546027#M9839</link>
    <description>&lt;P&gt;Once RACF logs have been located, where would I need to send them so that they could be sent to Splunk?&amp;nbsp; In simple terms, I would assume that they would need to be sent to a Syslog server by following the below process?&amp;nbsp; Also, I do not think TA's like Ironside or SFSherlock or IBM Common Data Provider for z Systems are required, or are they?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;1.)&amp;nbsp; Forward SMF logs from&amp;nbsp;&lt;SPAN&gt;z/OS system to Syslog into their own dedicated directory&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.)&amp;nbsp; On the Syslog server configure the inputs.conf/monitoring stanza to look for those SMF logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3.)&amp;nbsp; The UF that is installed on the Syslog server is configured via its outputs.conf file to forward to the&amp;nbsp; IDX or HF for parsing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4.) IDX or HF (props.conf) the logs are parsed and then sent down to Splunk&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Mar 2021 14:42:24 GMT</pubDate>
    <dc:creator>itsmevic</dc:creator>
    <dc:date>2021-03-30T14:42:24Z</dc:date>
    <item>
      <title>RACF Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/RACF-Logs/m-p/546027#M9839</link>
      <description>&lt;P&gt;Once RACF logs have been located, where would I need to send them so that they could be sent to Splunk?&amp;nbsp; In simple terms, I would assume that they would need to be sent to a Syslog server by following the below process?&amp;nbsp; Also, I do not think TA's like Ironside or SFSherlock or IBM Common Data Provider for z Systems are required, or are they?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;1.)&amp;nbsp; Forward SMF logs from&amp;nbsp;&lt;SPAN&gt;z/OS system to Syslog into their own dedicated directory&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.)&amp;nbsp; On the Syslog server configure the inputs.conf/monitoring stanza to look for those SMF logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3.)&amp;nbsp; The UF that is installed on the Syslog server is configured via its outputs.conf file to forward to the&amp;nbsp; IDX or HF for parsing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4.) IDX or HF (props.conf) the logs are parsed and then sent down to Splunk&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 14:42:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/RACF-Logs/m-p/546027#M9839</guid>
      <dc:creator>itsmevic</dc:creator>
      <dc:date>2021-03-30T14:42:24Z</dc:date>
    </item>
  </channel>
</rss>

