All Apps and Add-ons

Mainframe Syslogs Plugin for Splunk

gloveman71
New Member

Is there a Splunk plugin available that would map/tag most of the recognized fields in the z/OS System Log?? Trying to pull out specific data, but most if not all of the fields are not mapped.

Thanx,
Jim Glover
james.glover@medmutual.com

Tags (2)
0 Karma

tldenney
Path Finder

IBM Common Data Provider for z Systems (CDPz) is the best option for sending Mainframe logs to Splunk.

CDPz can send a wide variety of data including 140 data sources and 100+ SMF record types. More specifically, CDPz can support the following:

• SMF records
• SYSLOG (IBM z/OS System Log and USS SyslogD)
• JOBLOGs
• Application logs (IBM CICS Transaction Server logs and IBM WebSphere Application Server logs)

CDPz also has advanced filtering capabilities including RegEx and time filtering that can be set up using the built-in web configuration tool shown below.

alt text

More information on IBM Common Data Provider for z Systems can be found directly on Splunkbase.

tldenney
Path Finder

The following Splunk Blog outlines how Splunk and IBM are partnering to help customers integrate IBM Z (Mainframe) Data and Insights into Splunk software:

https://www.splunk.com/blog/2017/08/22/insane-in-the-mainframe-splunk-and-ibm-partner-to-provide-end...

0 Karma

jreda
Explorer

Ironstream from Syncsort can do all of this work for you. It will handle all of the issues related to SYSLOG, z/OS SMF records, log4j and flat files. It deals with the compression, the triplets, the binary data and converts the data from EBCDIC to ASCII. It does this very efficiently, even offloading a lot of the work to a zIIP engine in order to keep the MSU cost of this work to an absolute minimum. This is all done in real time to give you the best data latency possible while not impacting the existing workload on your system.

yasinbi
New Member

Do you know how can i connect ironstream from syncsort with SPlunk ?

0 Karma

jeastman
Path Finder

You can go to http://www.syncsort.com/en/TestDrive/Ironstream-Starter-Edition to obtain Ironstream Starter Edition. The free Ironstream Starter Edition allows you to forward unlimited SYSLOG log data to Splunk. You simply need to download the product from the link provided, unterse some files, authorize the library, and setup the config file on the mainframe to get Ironstream up and running. To receive data on the Splunk end, you need a TCP input that accepts JSON formatted data (Ironstream cannot forward to a SPLUNKTCP port).

0 Karma

yasinbi
New Member

I already installed ironstream and it's up and running. My question is about create a connection between these two products. Ironstream and SPlunk are not talking from TCP connection. At the SPlunk site port definition and at the z/OS site splunk indexer IP and port definitions are all unknown for my installation.
Do you know any manual document about TCP connection?

0 Karma

jeastman
Path Finder

Do you have a TCP port configured on your Splunk server? This is required for Ironstream data to be accepted by Splunk.

Is your Splunk instance configured to only accept SSL connections? If so, have you setup your Ironstream instances and mainframe for this?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...