Hi All,
Pardon me if post wrong topic here since I'm very newbie in IBM Mainframe and its programming language used. I have query about IBM Mainframe syslog. I have a sample of syslog for IBM Mainframe and how do I read it according to its column. I have seen others type of syslog but IBM Mainframe totally difference. Actually I need to do parser for IBM Mainframe to integrate with SIEM. From there SIEM will pull Mainframe syslog and analyze it. I'm very newbie and can say not even know anything about IBM Mainframe, I need help on this. Please help me.
Sample of logs :
1 SDSF SYSLOG PRINT STC32183 DATA SET 117 SYSID IBMainframe DATE 08/22/2015 2015.234 LINE 85,980 PAGE 1
0M 4000000 IBMainframe 15234 07:00:01.44 STC32260 00000090 BPXF024I (OMVSKERN) Aug 22 07:00:01 CDRM51 syslogd: FSUM1230 Log file
S 437
E 437 00000090 /OPER/syslogd/08/22/local0 was created
M 4000000 IBMainframe 15234 07:00:01.44 STC32260 00000090 BPXF024I (OMVSKERN) Aug 22 07:00:01 CDRM51 syslogd: FSUM1230 Log file
S 438
E 438 00000090 /OPER/syslogd/08/22/local4 was created
M 4000000 IBMainframe 15234 07:00:01.44 STC32260 00000090 BPXF024I (OMVSKERN) Aug 22 07:00:01 CDRM51 syslogd: FSUM1230 Log file
S 439
E 439 00000090 /OPER/syslogd/08/22/log was created
M 4000000 IBMainframe 15234 07:00:01.44 STC32260 00000090 BPXF024I (OMVSKERN) Aug 22 07:00:01 CDRM51 syslogd: FSUM1230 Log file
S 440
E 440 00000090 /OPER/syslogd/08/22/Q5D1BRK was created
M 4000000 IBMainframe 15234 07:00:01.45 STC32260 00000090 BPXF024I (OMVSKERN) Aug 22 07:00:01 CDRM51 syslogd: FSUM1230 Log file
S 441
E 441 00000090 /OPER/syslogd/08/22/IKED was created
N 0140000 IBMainframe 15234 07:00:01.45 STC32260 00000090 FSUM1252 SYSLOGD RECONFIGURATION COMPLETE
N 0200000 IBMainframe 15234 07:00:01.46 JOB77202 00000281 $HASP100 OPERLVTC ON INTRDR FROM STC32191
S OPC1
N 0000000 IBMainframe 15234 07:00:01.47 JOB77202 00000290 IRR010I USERID OPCC IS ASSIGNED TO THIS JOB.
M 4000000 IBMainframe 15234 07:00:01.56 STC32219 00000281 EQQE037I JOB LOGDLY1 ( ), OPERATION(0010), IN APPLICATION 445
E 445 00000281 SYSLOG#DAILY , IS LATE, WORK STATION = CPU1, IA = 1508212350
N 0200000 IBMainframe 15234 07:00:01.57 JOB77203 00000281 $HASP100 SMFDLY1I ON INTRDR FROM STC32191
S OPC1
N 0000000 IBMainframe 15234 07:00:01.57 JOB77203 00000290 IRR010I USERID OPCC IS ASSIGNED TO THIS JOB.
N 0200000 IBMainframe 15234 07:00:01.67 JOB77204 00000281 $HASP100 SMFDLY2I ON INTRDR
I'm notice have paging count in the syslog.
S ----PAGING COUNTS---
N 0004000 IBMainframe 15234 07:00:02.58 JOB77203 00000290 -JOBNAME STEPNAME PROCSTEP RC EXCP CPU SRB CLOCK SERV PG
S PAGE SWAP VIO SWAPS STEPNO
N 0004000 IBMainframe 15234 07:00:02.58 JOB77203 00000290 -SMFDLY1I SWITCH 00 10 .00 .00 .00 303 0
1 SDSF SYSLOG PRINT STC32183 DATA SET 117 SYSID IBMainframe DATE 08/22/2015 2015.234 LINE 86,033 PAGE 2
0S 0 0 0 0 1
N 0200000 IBMainframe 15234 07:00:02.62 JOB77211 00000281 $HASP100 DPEBKBFM ON INTRDR DPEBKBFM FROM STC32191
S OPC1
N 0000000 IBMainframe 15234 07:00:02.62 JOB77211 00000290 IRR010I USERID OPCC IS ASSIGNED TO THIS JOB.
N 0200000 IBMainframe 15234 07:00:02.73 JOB77212 00000281 $HASP100 MALNNJ01 ON INTRDR MALNNJ01 FROM STC32191
S OPC1
N 4000000 IBMainframe 15234 07:00:02.99 JOB77206 00000090 $HASP373 HSMRECYC STARTED - INIT 4 - CLASS A - SYS IBMainframe
N 0020000 IBMainframe 15234 07:00:03.04 JOB77207 00000090 ICH70001I OPCC LAST ACCESS AT 07:00:02 ON SATURDAY, AUGUST 22, 2015
N 0020000 IBMainframe 15234 07:00:03.04 JOB77208 00000090 ICH70001I OPCC LAST ACCESS AT 07:00:03 ON SATURDAY, AUGUST 22, 2015
N 4000000 IBMainframe 15234 07:00:03.09 JOB77207 00000090 $HASP373 BKEBKRPT STARTED - INIT 5 - CLASS A - SYS IBMainframe
N 4000000 IBMainframe 15234 07:00:03.09 JOB77208 00000090 $HASP373 DA$DCOLL STARTED - INIT 6 - CLASS A - SYS IBMainframe
N 0004000 IBMainframe 15234 07:00:03.15 JOB77206 00000290 - --TIMINGS (MINS.)--
S ----PAGING COUNTS---
N 0004000 IBMainframe 15234 07:00:03.15 JOB77206 00000290 -JOBNAME STEPNAME PROCSTEP RC EXCP CPU SRB CLOCK SERV PG
S PAGE SWAP VIO SWAPS STEPNO
N 0004000 IBMainframe 15234 07:00:03.15 JOB77206 00000290 -HSMRECYC DISPLAY 00 20 .00 .00 .00 374 0
S 0 0 0 0 1
NC0000000 IBMainframe 15234 07:00:03.18 INTERNAL 00000290 START DUMPXY,DSNAME=SYS1.IBMainframe.MAN1
N C020000 IBMainframe 15234 07:00:03.18 00000090 IEFU29 HAS ISSUED 'START DUMPXY,DSNAME=SYS1.IBMainframe.MAN1
S '
N 0000000 IBMainframe 15234 07:00:03.18 00000290 IEF196I IEFU29 HAS ISSUED 'START DUMPXY,DSNAME=SYS1.IBMainframe.MAN1
N 0000000 IBMainframe 15234 07:00:03.18 00000290 IEF196I '
M 4000000 IBMainframe 15234 07:00:03.18 00000090 IEE388I SMF NOW RECORDING ON VOLSER OIBMainframe1, DSN=SYS1.IBMainframe.MAN2 TIME= 489
E 489 00000090 07.00.03
N 0200000 IBMainframe 15234 07:00:03.32 STC77213 00000281 $HASP100 DUMPXY ON STCINRDR
N 0004000 IBMainframe 15234 07:00:03.33 JOB77202 00000290 -