<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting data from Mainframe system?? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39920#M178845</link>
    <description>&lt;P&gt;Hi - check out the Mainframe Event Acquisition System (MEAS) which will send mainframe data to Splunk.  Events such as security activity, database accesses, CICS transaction activity, dataset access, FTP, TCPIP, RMF, SMP/E and more.  You have the ability to filter so that you can send only what you really want to Splunk for further alerting and reporting.  &lt;A href="http://www.meas-info.com"&gt;www.meas-info.com&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2013 15:50:39 GMT</pubDate>
    <dc:creator>BobFake</dc:creator>
    <dc:date>2013-08-19T15:50:39Z</dc:date>
    <item>
      <title>Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39914#M178839</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;
How to get data from Mainframe systems onto Splunk??&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 12:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39914#M178839</guid>
      <dc:creator>shri_27</dc:creator>
      <dc:date>2013-05-20T12:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39915#M178840</link>
      <description>&lt;P&gt;Can you syslog messages from the mainframe?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 13:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39915#M178840</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2013-05-20T13:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39916#M178841</link>
      <description>&lt;P&gt;I have looked into this in the past. You will more than likely need to use some 3rd party software to create metrics that Splunk will collect.  There are currently no Splunk Apps/built in functionality (a side from using syslog) for doing this. This company seemed to have a solution that would plug into Splunk &lt;A href="http://www.infosecinc.com/meas.php"&gt;http://www.infosecinc.com/meas.php&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 14:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39916#M178841</guid>
      <dc:creator>cramasta</dc:creator>
      <dc:date>2013-05-20T14:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39917#M178842</link>
      <description>&lt;P&gt;There is no forwarder code for mainframe systems today.  You could always submit a feature request asking for it.  If you don't, then chances are it will never happen.  (Splunk product management does not look at Splunkbase questions around a particular topic as a proxy for actual feature requests)&lt;/P&gt;

&lt;P&gt;Also, you need to be explicit about what you are looking for.  There are at least 3 common "mainframe" operating systems, and programs compiled for one WILL NOT work on the other.  You have:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;z/OS (MVS)&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;z/VM&lt;/LI&gt;
&lt;LI&gt;Linux (s390 architecture)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;All of these are "mainframe" operating systems, each with their own APIs and idiosyncracies.  When 99% of all people think "mainframe" they are thinking of z/OS, but the alternatives exist.  (Functionally speaking, Linux/s390 would be the least difficult for Splunk to port a forwarder to - the other two could be much worse)&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 14:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39917#M178842</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2013-05-20T14:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39918#M178843</link>
      <description>&lt;P&gt;I'm pretty certain some forwarders for mainframes are coming in Splunk 6. You should check with your account rep.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 19:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39918#M178843</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2013-06-21T19:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39919#M178844</link>
      <description>&lt;P&gt;I did a little exploration with a third party about getting performance metrics off of Nonstop/Tandem hardware.   We wrote a program to collect the metrics and write them out using a vaguely sensible format to a socket.   Then it was just a simple TCP input in the Splunk server and some extractions.       It was quite a successful prototype and proof-of-concept although we didn't end up releasing the product. &lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 23:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39919#M178844</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-06-21T23:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39920#M178845</link>
      <description>&lt;P&gt;Hi - check out the Mainframe Event Acquisition System (MEAS) which will send mainframe data to Splunk.  Events such as security activity, database accesses, CICS transaction activity, dataset access, FTP, TCPIP, RMF, SMP/E and more.  You have the ability to filter so that you can send only what you really want to Splunk for further alerting and reporting.  &lt;A href="http://www.meas-info.com"&gt;www.meas-info.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 15:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39920#M178845</guid>
      <dc:creator>BobFake</dc:creator>
      <dc:date>2013-08-19T15:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39921#M178846</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Splunk 6 has been released, and there is no UF for mainframe. Do you know if it is going to be released later this year?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 13:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39921#M178846</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2013-10-11T13:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39922#M178847</link>
      <description>&lt;P&gt;We FTP our Mainframe logs every 5 minutes to a text file on a heavy forwarder. The logs are forwarded on from there and load balanced across our indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 13:51:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39922#M178847</guid>
      <dc:creator>watsm10</dc:creator>
      <dc:date>2013-10-11T13:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39923#M178848</link>
      <description>&lt;P&gt;Hi - if you need to get mainframe data (security, database, CICS, FTP, TCPIP, master console messages and much more), please see meas-info.com. Our Mainframe Event Acquisition System (MEAS)product will allow you to monitor, filter and forward - in real time - any/all events from the mainframe that you would like to see in Splunk.  It take roughly 1/2 day to install and no IPL necessary.  Please give us a call if you need any more information.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2014 16:27:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39923#M178848</guid>
      <dc:creator>BobFake</dc:creator>
      <dc:date>2014-02-24T16:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39924#M178849</link>
      <description>&lt;P&gt;Ironstream from Syncsort can do all of this work for you. It will handle all of the issues related to SYSLOG, z/OS SMF records, log4j and flat files. It deals with the compression, the triplets, the binary data and converts the data from EBCDIC to ASCII. It does this very efficiently, even offloading a lot of the work to a zIIP engine in order to keep the MSU cost of this work to an absolute minimum. This is all done in real time to give you the best data latency possible while not impacting the existing workload on your system. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 21:29:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39924#M178849</guid>
      <dc:creator>jreda</dc:creator>
      <dc:date>2015-02-04T21:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39925#M178850</link>
      <description>&lt;P&gt;&lt;STRONG&gt;IBM Transaction Analysis Workbench for z/OS&lt;/STRONG&gt; ("Workbench") can forward a wide range of logs from various z/OS subsystems to Splunk.&lt;/P&gt;

&lt;P&gt;Recent enhancements to Workbench include features specifically for streaming logs in JSON Lines format off z/OS to a Splunk TCP data input.&lt;/P&gt;

&lt;P&gt;Some key points about log forwarding with Workbench:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Workbench does not require special agent software to collect log data. Instead, Workbench uses the logs and other historical data that each subsystem generates during normal transaction processing and system operations.&lt;/LI&gt;
&lt;LI&gt;Forward the fields you want, from the records you want, when you want:

&lt;UL&gt;
&lt;LI&gt;Workbench does not limit you to forwarding a fixed subset of fields from each record type. You can select as many or as few fields as you want.&lt;/LI&gt;
&lt;LI&gt;You can filter records for forwarding based on combinations of field values.&lt;/LI&gt;
&lt;LI&gt;Workbench log forwarding is not real-time. To forward logs with Workbench, you run batch jobs on z/OS. You decide when to run those jobs, and how often.&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Simple, self-contained JCL. Streaming a log as JSON Lines to a Splunk TCP data input involves about a dozen lines of self-contained JCL.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Example JCL to forward CICS monitoring facility (CMF) performance class (SMF type 110) records from a dumped SMF data set:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;//S1       EXEC PGM=FUWBATCH
//STEPLIB  DD   DISP=SHR,DSN=FUW.SFUWLINK
//LOGIN    DD   DISP=SHR,DSN=SMF.MVS1(-1)
//SYSPRINT DD   SYSOUT=*
//SYSIN    DD   *
STREAM NAME(SPLUNK) TRANSPORT(TCP) HOST(mysplunk) PORT(6789) +
       LINES FLAT OMITNULL NOTITLE FIELDCASE(LOWER) ASCII LF ZONE
JSON STREAM(SPLUNK) CODE(CMF)
FIELDS(
* Insert list of CMF fields you want to forward
)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Related &lt;A href="https://github.com/fundisoftware/fuw-splunk-app"&gt;Splunk app on GitHub&lt;/A&gt; (currently just one dashboard, for CICS performance).&lt;/P&gt;

&lt;P&gt;Some relevant topics in the Workbench (version 1.3) product documentation:&lt;/P&gt;

&lt;P&gt;Getting started ► Overview ► Features ► &lt;A href="http://www.ibm.com/support/knowledgecenter/SSKKZM_1.3.0/fuwucon_forward.htm"&gt;Log forwarding&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Forwarding logs to analytics platforms ► &lt;A href="http://www.ibm.com/support/knowledgecenter/SSKKZM_1.3.0/fuwucon_forward_splunk.htm"&gt;Splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Extracting logs to CSV or JSON ► &lt;A href="http://www.ibm.com/support/knowledgecenter/SSKKZM_1.3.0/fuwutsk_json_lines_streaming_tcp.htm"&gt;Streaming JSON Lines over TCP&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Disclosure:&lt;/STRONG&gt; I am the author of the Workbench product documentation.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2016 07:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39925#M178850</guid>
      <dc:creator>Graham_Hanningt</dc:creator>
      <dc:date>2016-11-11T07:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39926#M178851</link>
      <description>&lt;P&gt;IBM has a product: IBM Common Data Provider for z Systems v1.1.&lt;BR /&gt;
It provides for near real-time SMF and various log streaming or in batch.&lt;BR /&gt;
check it out at: ibm.biz/CDPzInfo&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 20:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39926#M178851</guid>
      <dc:creator>bklutz</dc:creator>
      <dc:date>2016-12-01T20:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39927#M178852</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.ibm.com/us-en/marketplace/common-data-provider-for-z-systems"&gt;IBM Common Data Provider for z Systems&lt;/A&gt;&lt;/STRONG&gt; can forward mainframe data to Splunk in near real-time. &lt;/P&gt;

&lt;P&gt;It supports a wide variety of data including 140 data sources and 100+ SMF record types, and it can stream structured and unstructured data or use batch mode to collect data. IBM Common Data Provider for z Systems also has advanced filtering capabilities including RegEx and time filtering.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/51iFCA60180F2644E9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;You can also learn more about IBM Common Data Provider directly on &lt;A href="https://splunkbase.splunk.com/app/3615/"&gt;Splunkbase&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 18:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39927#M178852</guid>
      <dc:creator>tldenney</dc:creator>
      <dc:date>2017-06-23T18:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39928#M178853</link>
      <description>&lt;P&gt;I downvoted this post because not really true, there are a variety of forwarding options on the market like ibm's common data provider... although appreciate this post might have been correct when initially written!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2017 18:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39928#M178853</guid>
      <dc:creator>mattwhitbourne</dc:creator>
      <dc:date>2017-06-26T18:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39929#M178854</link>
      <description>&lt;P&gt;It is based on 30+ years of experienced IBM engineers, to learn more take a look here : ibm.biz/CDPzInfo&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2017 07:38:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39929#M178854</guid>
      <dc:creator>DomenicoDAlteri</dc:creator>
      <dc:date>2017-06-27T07:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39930#M178855</link>
      <description>&lt;P&gt;With Syncsort Ironstream, you can collect log data from SMF, RMF, Syslog and other z/OS sources, and forward that data in real time to the Splunk® Enterprise analytics platform. That gives you visibility into your z/OS environment.  Ironstream also integrates with Splunk’s Enterprise Security and IT Service Intelligence applications. This goes beyond IT operational analytics to give you a firmer grasp of potential security threats in your z/OS environment. It ensures that your critical business services are being delivered on time.&lt;BR /&gt;
For more information on Ironstream: &lt;A href="http://www.syncsort.com/en/Products/Mainframe/Ironstream"&gt;http://www.syncsort.com/en/Products/Mainframe/Ironstream&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 15:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39930#M178855</guid>
      <dc:creator>ehall0328</dc:creator>
      <dc:date>2017-09-15T15:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39931#M178856</link>
      <description>&lt;P&gt;Splunk and IBM recently hosted a joint webinar on how they are partnering to help customers gain access to mainframe machine data more quickly for real-time investigation, analytics, and pattern analysis. You can watch the replay here: &lt;A href="https://onlinexperiences.com/scripts/Server.nxp?LASCmd=AI:4;F:QS!10100&amp;amp;ShowKey=43016&amp;amp;AffiliateData=Flyer"&gt;https://onlinexperiences.com/scripts/Server.nxp?LASCmd=AI:4;F:QS!10100&amp;amp;ShowKey=43016&amp;amp;AffiliateData=Flyer&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 18:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/39931#M178856</guid>
      <dc:creator>tldenney</dc:creator>
      <dc:date>2017-09-28T18:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Mainframe system??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/561110#M178857</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;@Anonymous&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you get your question answered?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you need to get mainframe data (security, database, CICS, FTP, TCPIP, master console messages and much more), please see dgtechllc.com/meas. Our Mainframe Event Acquisition System (MEAS) product will allow you to monitor, filter and forward - in real time - any/all events from the mainframe that you would like to see in Splunk. It takes&amp;nbsp;roughly&lt;STRONG&gt; 1/2 day to install&lt;/STRONG&gt; and &lt;STRONG&gt;no IPL necessary&lt;/STRONG&gt;. Please give us a call if you need anymore information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks! &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 21:32:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Mainframe-system/m-p/561110#M178857</guid>
      <dc:creator>CurtisGannaway</dc:creator>
      <dc:date>2021-07-27T21:32:14Z</dc:date>
    </item>
  </channel>
</rss>

