SlideShare a Scribd company logo
Downtime
is Not an Option
Integrating IBM Z into ServiceNow & Splunk
Ian Hartley I Product Management Director
® ®
Downtime is Not an Option
• : Outages happen
• : Failures & missed SLAs are costly
• : Reputations are damaged
Online outages, delays continue to impact Costco shoppers
The issues were a major problem on Thanksgiving and again on Black Friday
*https://www.atlassian.com/incident-management/kpis/cost-of-downtime
Average estimate…
$9K per minute!*
Everyone’s Watching…
…You Need to See First!
3
Everyone’s Sharing…
…Your Failures!
4
Wait a minute…
We are talking about MAINFRAMES
They are rock solid & secure…
…right!?
Maybe…
• Mainframe is not a static environment
• System & application changes take place
• Most system outages are due to human error
…and mainframe is no exception
• Mainframe remains a mission-critical platform
• Supports vital services connected to the rest of the
enterprise stack
• When a service fails… the broader organization needs
visibility into the mainframe to trouble-shoot
…and resolve FAST
• Better still? Get visibility of issues BEFORE they occur
Today’s IT is Complex – Need 360° Visibility
7 Mainframe
Legacy IBM systems are left out of today’s
leading IT analytics & operations platforms
Distributed and
Cloud environments
Mainframe and
IBM i Systems
IBM Z
Mainframe
IBM i
System
8
Big Iron to
Big Data
Analytics
Challenges
Systems Management Facility
(SMF), Syslog, Log4j web and
application logs, RMF, RACF,
USS files and standard datasets
Complex data structures
(SMF) with headers, product
sections, data sections,
variable length and self-
describing
• EBCDIC not recognized
outside of the mainframe
world
• Binary flags and fields
9
Millions of log records
generated daily – 9.7TB
average daily mainframe log
data …and growing
Not real-time, typically have to
wait overnight for an offload
Typical daily FTP
upload/downloads can’t get
granular
Ironstream Removes the Barrier
Enables 360° visibility
IBM Z
Mainframe
IBM i
System
360°
view across
the enterprise
10
Use Cases
• Monitor operational status of enterprise IT infrastructure
• Make better decisions to take control of the IT infrastructure
• Monitor resource utilization & availability
• Problem detection & isolation
• Reduce MTTI, MTTR
• Meet SLAs
• System health, KPI monitoring with Splunk IT Service Intelligence
• Detect & mitigate security threats
• Privileged activity, anomalies, data movement
• Achieve compliance
• Pass audits
• Comprehensive surveillance with Splunk Enterprise Security
Ironstream for ServiceNow
13 © 2019 ServiceNow, Inc. All Rights Reserved. Confidential.
Deliver high-performing business services
with visibility and AIOps
Deliver
business service
health with AIOps
Establish
complete visibility across
your operations estate
CMDB
Optimize
spend on cloud
usage and software
Ironstream Integration with ServiceNow Discovery
• Rapidly configure and launch secure discovery of IBM i
and mainframe resources and their relationships
• Auto-populate and maintain the ServiceNow
Configuration Management Database (CMDB)
• Automatically map dependencies & assign relationships
• Get a single view of entire infrastructure to enable
smarter IT decisions
• Reduce decision times and errors, increase productivity
with intelligent automation
14
MID Server
Agent
Mainframe or IBM i LPAR
Discovery Agent
MID Server
IMSMQ
Db2 CICS
Network
Host
Resources
Probes sent to run
discovery scripts
Scripts execute
commands
Client runs command
against agent
Agent executes
commands on LPAR
Agent sends output
back to client
1
2
3
4
5
6Sensor parses output
and creates CIs
Resources and Subsystems
Discovery Workflow
REXX
VTAM
MQ Commands
MVS
Db2 Queries
Ironstream
MCS
Ironstream for
ServiceNow
Discovery
• DB2 - DDF, DSG, databases,
table spaces and deep
configuration data
• Completed jobs
• DASD storage
• Storage groups
• CICS - regions, transactions,
programs
• IMS - regions, databases,
transactions, programs
• MQ - managers, channels,
queues
• Memory
• LPAR
• CPU
• Network connectivity
• Installed IBM/non-IBM software
• Local Storage with ASPs
• Memory
• LPAR
• CPU
• Network connectivity
• Installed software
• Selected system values
• Subsystems
• Active jobs
• Job queues
• Output queues
• Libraries
• Program objects
Ironstream Integration with ServiceNow
Event Management
• Extends cross-platform capabilities of
ServiceNow ITOM to include mission-critical
IBM mainframe & IBM i environments
• Significantly reduces event noise and floods
generated by third-party monitoring tools,
• Monitor service health
• Prevent outages
• Easily take action
• Sophisticated z/OS and IBM i event status
management of any messages which go
through the console to establish proactive
enterprise systems management
MAINFRAME 1
MAINFRAME 2
MID Server
Agent
Mainframe or IBM i LPAR
Ironstream
MCS
Event Mngmnt
Agent
MID Server
JES,
SDSF
MQ
Db2 CICS
Network
Host
Resources
Integrates with
Event Management
Passes to MID Server
MCS filters & formats
messages/information
Agent detects
messages, runs scripts,
commands etc. on LPAR
Agent sends output
to client
5
4
3
1
2
6
Leverages workflow to
process & automate
Resources and Subsystems
Event Management Workflow
REXX
VTAM
NetView
MVS
TCP/IP
Ironstream for
ServiceNow
Event
Management
• 110+ Event Rules including:
• System Console/Syslog Events
• CICS Transient Data Queue
Events
• IMS Master Terminal Operator
Events
• Interval Monitoring
• SMS Group Threshold
Monitoring
• MQ Manager, Channels,
Queues
• Active Jobs
• RMF based Performance
Monitoring
• Custom Message Interface
• Message Automation
• Reliable TCP Communication
• Heartbeat and positive message
acknowledgement
• Message Buffering
• Command Console
• 170+ Rules for IBM i, including:
• AS/400 State
• ASP State
• Audit Journal Alerts
• Job Queue State
• Job/Subsystem State
• Memory Pool State
• Threshold Monitoring
• I/O per second
• TIMW Status
• Message Queue Alerts
• MQ Series States
• TCP Connection Status
• CMTW Status
• MTXW Status
• Output Queue State
• Services State
• Agent Connection
• Wait Status Monitoring
Discovery
Event Management Rules
Event Management Workflow
Ironstream for Splunk
Splunk: Industry-Leading Platform For Machine Data
Online
Services
Web
Services
Servers
Security GPS
Location
Storage
Desktops
Networks
Packaged
Application
s
Custom
Apps
Messagin
g
Telecoms
Online
Shopping
Cart
Web
Clickstreams
Databases
Energy
Meters
Call Detail
Records
Smartphones
and Devices
RFID
On-Premises
Private
Cloud
Public
Cloud
Enterprise Scalability
Universal Indexing
Developer
Platform
Report &
analyze
Custom
dashboards
Monitor
& alert
Ad hoc
search
!
24
Comprehensive Security & Operational Metrics
Disk Information
• Reads/Writes
• Disk Capacity
• Disk Space Availability
• Disk Busy
• Disk Response Times
Job Information
• CPU used
• Socket sends/receives
• Stream file, directory & Symlink reads
• Stream file writes
• Seize/Wait time
• Communication Puts/Gets
CPU information Per Virtual CPU
• Time used
• Number of CPUs active
TCP communications
• Detailed stats at Datagram
• Fragmentation information
Physical Processor information per CPU
• Time used
• Owning Partition
Virtual Processor information per Virtual CPU
• Status, Time active, Time used.
• Configured/Uncapped available time
• Instruction count
Memory pool information per Pool
• Database faults
• Non-database faults
• Job transitions Size
• Disk I/O stats
• Pages aged and stolen
Job summary information
• CPU used
• Disk I/O detail
• Database/Non-database
• Page faults
• I/O Pending faults
Security Information
• User Profiles
• System Values
• Object attributes & authorities
• Authorization Lists, Job Descriptions
• Commands
• Active Jobs, Spool Files
• Changes to values, authorities, profiles, auth. lists
• Access attempts (authentication or object access)
• Sensitive object access
Four Key Use Cases addressed with Ironstream
and Splunk
• Response times/SLAs
• Latencies
• Exceptions
• Resource utilization
• Sensitive data access
& movement (PII/PHI)
• Configuration settings
(e.g. FISMA)
• IRS Pub 1075
• PCI DSS
• Incident triage
• Anomalous behavior
detection
• Glass table view of
entire service process
• Predictive analytics
• User Authentications
• Account & login activity
• FTP sessions & file
activity
Security
Operational
Intelligence
IT
Monitoring
Compliance
26
Precisely
Ironstream
for Splunk
360ᵒ View:
• High performance, real-time
collection of IBM mainframe
information
• Normalizes the z/OS data so it can
be used by Splunk
• Same Splunk dashboards, bigger,
more complete data sets; free apps
• Network managers, security
analysts, application analysts,
enterprise architects can use
without requiring mainframe
access or expertise
27
What does Ironstream provide for Splunk?
28
• High performance, cost-effective platform for collecting critical
log, machine, and event data
• Normalization of mainframe and IBM i data for off-platform
analytics & operations engines, including cloud
• Completes the enterprise-wide picture of IT infrastructure
• Better visibility
• Better agility
• Better control
• Addresses the SME challenge: Used by network managers,
security analysts, application analysts, enterprise architects
without requiring detailed mainframe or IBM i access or
expertise
29
Example Dashboards powered by Ironstream
Security
• Authorization Failures
• Change Profile Events
• System Value Changes
• User Activities
Operations
• Capacity Monitoring
• CPU Utilization
• Create/Delete objects
• Disk Performance
• Job Durations
• LPAR Performance
• Message Queue Events
• System Performance
Application Data
• Employee Database Use Case
Splunk Dashboards
Ironstream for Splunk works with Mainframe Data
Precisely
Ironstream
Data
Forwarder
TCP/IP
Ironstream
Desktop
DCE IDT
Data Collection
Extension
Real-time Collection
Assembler C,
COBOL,
REXX
!
Data Sources
HTTP(S)
SMF RMF
File
Load
Log4j IMSSYSLOG
SYSLOGD
System
State
SYSOUT
Live SPOOL
Db2 USS
Alerts
Network
Components
Forwarder
API
Ironstream for
Splunk
Splunk
Enterprise
IT Service
Intelligence
Powerful insights of your enterprise
for IT Operations and Security with
Ironstream for Splunk
Precisely Ironstream integrates with
the Splunk ITSI premium app to
predict and prevent service
degradation with a unified
monitoring experience
Enterprise
Security
Data Model
for Mainframe
Precisely Ironstream integrates with
the Splunk Enterprise Security
premium app to provide enterprise-
wide view of security across all
platforms
The Precisely Ironstream Data
Model provides a structured and
logical view of mainframe log data
elements in Splunk for faster
searching, analysis and Splunk
development
Downtime is Not an Option: Integrating IBM Z into ServiceNow and Splunk
Customer Stories
Achieving a Single Source of Truth
with Ironstream for ServiceNow
Need for visibility across all IT
infrastructure in ServiceNow –
including mainframe
• Rely on ServiceNow CMDB as
“single source of truth”
• No comprehensive coverage
for mainframe
100’s business application touch
mainframe
• Mainframe key resource
• No insight – constant demand
on mainframe team
• Manual integration
• Too costly
• Impossible to maintain
• Out-of-date before complete
Ironstream for ServiceNow
• Certified ServiceNow solution
• Simple install & configuration
• Seamless integration with
ServiceNow Discovery
• Auto-populates & maintains
CMDB
• Auto-maps dependencies &
relationships
• Improved IT visibility
• Complete, accurate, up-to-date
CMDB
• Visibility of all IT infrastructure
• Visibility of relationships,
connections & dependencies
• Better agility
• Improved service availability
• Better change management
• Significant reductions
• People-hours
• Related costs
Challenge Solution Results
Supporting
optimal service
delivery at U.S.
based Loan
Service Provider
with Ironstream
for Splunk
O B J E C T I V E
• To monitor mainframe IT operations to
track health of service delivery for Loan
Service Providers
• Capture mainframe business data in
support of system and application
monitoring in Splunk
C H A L L E N G E
• Required several data feeds including SMF,
SYSLOG and SYSOUT for batch job
monitoring
• Filtering the log data to selected jobs
• Loading business data from sequential files
S O L U T I O N
• Precisely Ironstream forwarding required
log data and filter it to specific messages
and jobs
• Splunk for IT operations analytics
B E N E F I T
• Increased visibility to support optimal
service delivery for loan service providers
• Fast time to value, with ease of installation
and configuration, in contrast to
competitive solutions
European bank
tackles PCI-DSS
compliance with
Ironstream for
Splunk
C H A L L E N G E
• Working against a tight deadline to
build a solution with Splunk to
continuously monitor all relevant
PCI DSS requirements.
• Needed a proven, easy-to-use
solution to include their busy,
complex mainframe environment,
which included 6 mainframes and
900+ production CICS regions
S O L U T I O N
• Ironstream for Splunk:
• Seamless integration to include
mainframe log data into Splunk
• Proven to be easier to install,
configure and use vs. competition
B E N E F I T
• Compliance with PCI DSS mandates
• Single, enterprise-wide monitoring
solution for all systems, including
mainframe
Thank you
precisely.com/integrate

More Related Content

PDF
Introduction of Oracle Database Architecture(抜粋版) - JPOUG Oracle Database入学式 ...
PDF
From the Splunk Front Lines: Unlocking Insights from IBM i Data
PDF
Making Legacy IBM Systems Visible in ServiceNow
PDF
Government Agencies Using Splunk: Is Your Critical Data Missing?
PPTX
Don't Leave Your Traditional IBM Systems Out of Your IT Operations Efforts
PPTX
Why Integrating IBM Z into ServiceNow and Splunk Is So Important
PDF
How to Get IBM i Security and Operational Insights with Splunk
PPTX
Introducing Ironstream Support for ServiceNow Event Management
Introduction of Oracle Database Architecture(抜粋版) - JPOUG Oracle Database入学式 ...
From the Splunk Front Lines: Unlocking Insights from IBM i Data
Making Legacy IBM Systems Visible in ServiceNow
Government Agencies Using Splunk: Is Your Critical Data Missing?
Don't Leave Your Traditional IBM Systems Out of Your IT Operations Efforts
Why Integrating IBM Z into ServiceNow and Splunk Is So Important
How to Get IBM i Security and Operational Insights with Splunk
Introducing Ironstream Support for ServiceNow Event Management

Similar to Downtime is Not an Option: Integrating IBM Z into ServiceNow and Splunk (20)

PDF
Get Mainframe Visibility to Enhance SIEM Efforts in Splunk
PDF
360-Degree View of IT Infrastructure with IT Operations Analytics
PPTX
How Precisely and Splunk Can Help You Better Manage Your IBM Z and IBM i Envi...
PPTX
Maximizing Service Maps To Include The Critical CIs on The Mainframe
PDF
Ironstream for IBM i - Enabling Splunk Insight into Key Security and Operatio...
PDF
Enterprise Security in Mainframe-Connected Environments
PDF
Top Use Cases for Mainframe and IBM i Discovery in ServiceNow®
PPTX
Enhance ServiceNow with Automated Discovery for Mainframe and IBM i
PDF
Controlling Access to IBM i Systems and Data
PPTX
Sys track customer facing-terminal server-updated
PDF
SIEM enabled risk management , SOC and GRC v1.0
PPTX
Getting a Deeper Look at Your IBM® Z and IBM i Data in ServiceNow
PPTX
FileNet Datacap Implementation Guideline
PPTX
Avoid the IT War Room: Integrate Mainframe and IBM i into ServiceNow
PPTX
Automate Data Scraping and Extraction for Web
PPTX
Knowledge Transfer Training Presentation for Identity Lifecycle Manager
PDF
Expand Your Control of Access to IBM i Systems and Data
PPTX
Financial Services Technology Leader Turns Mainframe Logs into Real-Time Insi...
PDF
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
PPTX
Government Webinar: Low-Cost Log, Network Configuration, and IT Monitoring So...
Get Mainframe Visibility to Enhance SIEM Efforts in Splunk
360-Degree View of IT Infrastructure with IT Operations Analytics
How Precisely and Splunk Can Help You Better Manage Your IBM Z and IBM i Envi...
Maximizing Service Maps To Include The Critical CIs on The Mainframe
Ironstream for IBM i - Enabling Splunk Insight into Key Security and Operatio...
Enterprise Security in Mainframe-Connected Environments
Top Use Cases for Mainframe and IBM i Discovery in ServiceNow®
Enhance ServiceNow with Automated Discovery for Mainframe and IBM i
Controlling Access to IBM i Systems and Data
Sys track customer facing-terminal server-updated
SIEM enabled risk management , SOC and GRC v1.0
Getting a Deeper Look at Your IBM® Z and IBM i Data in ServiceNow
FileNet Datacap Implementation Guideline
Avoid the IT War Room: Integrate Mainframe and IBM i into ServiceNow
Automate Data Scraping and Extraction for Web
Knowledge Transfer Training Presentation for Identity Lifecycle Manager
Expand Your Control of Access to IBM i Systems and Data
Financial Services Technology Leader Turns Mainframe Logs into Real-Time Insi...
Security Challenges in Cloud Integration - Cloud Security Alliance, Austin Ch...
Government Webinar: Low-Cost Log, Network Configuration, and IT Monitoring So...
Ad

More from Precisely (20)

PDF
The Future of Automation: AI, APIs, and Cloud Modernization.pdf
PDF
Unlock new opportunities with location data.pdf
PDF
Reimagining Insurance: Connected Data for Confident Decisions.pdf
PDF
Introducing Syncsort™ Storage Management.pdf
PDF
Enable Enterprise-Ready Security on IBM i Systems.pdf
PDF
A Day in the Life of Location Data - Turning Where into How.pdf
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
PDF
Solving the CIO’s Dilemma: Speed, Scale, and Smarter SAP Modernization.pdf
PDF
Solving the Data Disconnect: Why Success Hinges on Pre-Linked Data.pdf
PDF
Cooking Up Clean Addresses - 3 Ways to Whip Messy Data into Shape.pdf
PDF
Building Confidence in AI & Analytics with High-Integrity Location Data.pdf
PDF
SAP Modernization Strategies for a Successful S/4HANA Journey.pdf
PDF
Precisely Demo Showcase: Powering ServiceNow Discovery with Precisely Ironstr...
PDF
The 2025 Guide on What's Next for Automation.pdf
PDF
Outdated Tech, Invisible Expenses – How Data Silos Undermine Operational Effi...
PDF
Modernización de SAP: Maximizando el Valor de su Migración a SAP S/4HANA.pdf
PDF
Outdated Tech, Invisible Expenses – The Hidden Cost of Disconnected Data Syst...
PDF
Migration vers SAP S/4HANA: Un levier stratégique pour votre transformation d...
PDF
Outdated Tech, Invisible Expenses: The Hidden Cost of Poor Data Integration o...
PDF
The Changing Compliance Landscape in 2025.pdf
The Future of Automation: AI, APIs, and Cloud Modernization.pdf
Unlock new opportunities with location data.pdf
Reimagining Insurance: Connected Data for Confident Decisions.pdf
Introducing Syncsort™ Storage Management.pdf
Enable Enterprise-Ready Security on IBM i Systems.pdf
A Day in the Life of Location Data - Turning Where into How.pdf
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Solving the CIO’s Dilemma: Speed, Scale, and Smarter SAP Modernization.pdf
Solving the Data Disconnect: Why Success Hinges on Pre-Linked Data.pdf
Cooking Up Clean Addresses - 3 Ways to Whip Messy Data into Shape.pdf
Building Confidence in AI & Analytics with High-Integrity Location Data.pdf
SAP Modernization Strategies for a Successful S/4HANA Journey.pdf
Precisely Demo Showcase: Powering ServiceNow Discovery with Precisely Ironstr...
The 2025 Guide on What's Next for Automation.pdf
Outdated Tech, Invisible Expenses – How Data Silos Undermine Operational Effi...
Modernización de SAP: Maximizando el Valor de su Migración a SAP S/4HANA.pdf
Outdated Tech, Invisible Expenses – The Hidden Cost of Disconnected Data Syst...
Migration vers SAP S/4HANA: Un levier stratégique pour votre transformation d...
Outdated Tech, Invisible Expenses: The Hidden Cost of Poor Data Integration o...
The Changing Compliance Landscape in 2025.pdf
Ad

Recently uploaded (20)

PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
cuic standard and advanced reporting.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Cloud computing and distributed systems.
PDF
Encapsulation theory and applications.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Big Data Technologies - Introduction.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
NewMind AI Weekly Chronicles - August'25 Week I
Agricultural_Statistics_at_a_Glance_2022_0.pdf
sap open course for s4hana steps from ECC to s4
Diabetes mellitus diagnosis method based random forest with bat algorithm
Building Integrated photovoltaic BIPV_UPV.pdf
Understanding_Digital_Forensics_Presentation.pptx
20250228 LYD VKU AI Blended-Learning.pptx
Machine learning based COVID-19 study performance prediction
cuic standard and advanced reporting.pdf
Chapter 3 Spatial Domain Image Processing.pdf
Network Security Unit 5.pdf for BCA BBA.
MIND Revenue Release Quarter 2 2025 Press Release
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Cloud computing and distributed systems.
Encapsulation theory and applications.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Big Data Technologies - Introduction.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx

Downtime is Not an Option: Integrating IBM Z into ServiceNow and Splunk

  • 1. Downtime is Not an Option Integrating IBM Z into ServiceNow & Splunk Ian Hartley I Product Management Director ® ®
  • 2. Downtime is Not an Option • : Outages happen • : Failures & missed SLAs are costly • : Reputations are damaged Online outages, delays continue to impact Costco shoppers The issues were a major problem on Thanksgiving and again on Black Friday *https://www.atlassian.com/incident-management/kpis/cost-of-downtime Average estimate… $9K per minute!*
  • 5. Wait a minute… We are talking about MAINFRAMES They are rock solid & secure… …right!?
  • 6. Maybe… • Mainframe is not a static environment • System & application changes take place • Most system outages are due to human error …and mainframe is no exception • Mainframe remains a mission-critical platform • Supports vital services connected to the rest of the enterprise stack • When a service fails… the broader organization needs visibility into the mainframe to trouble-shoot …and resolve FAST • Better still? Get visibility of issues BEFORE they occur
  • 7. Today’s IT is Complex – Need 360° Visibility 7 Mainframe
  • 8. Legacy IBM systems are left out of today’s leading IT analytics & operations platforms Distributed and Cloud environments Mainframe and IBM i Systems IBM Z Mainframe IBM i System 8
  • 9. Big Iron to Big Data Analytics Challenges Systems Management Facility (SMF), Syslog, Log4j web and application logs, RMF, RACF, USS files and standard datasets Complex data structures (SMF) with headers, product sections, data sections, variable length and self- describing • EBCDIC not recognized outside of the mainframe world • Binary flags and fields 9 Millions of log records generated daily – 9.7TB average daily mainframe log data …and growing Not real-time, typically have to wait overnight for an offload Typical daily FTP upload/downloads can’t get granular
  • 10. Ironstream Removes the Barrier Enables 360° visibility IBM Z Mainframe IBM i System 360° view across the enterprise 10
  • 11. Use Cases • Monitor operational status of enterprise IT infrastructure • Make better decisions to take control of the IT infrastructure • Monitor resource utilization & availability • Problem detection & isolation • Reduce MTTI, MTTR • Meet SLAs • System health, KPI monitoring with Splunk IT Service Intelligence • Detect & mitigate security threats • Privileged activity, anomalies, data movement • Achieve compliance • Pass audits • Comprehensive surveillance with Splunk Enterprise Security
  • 13. 13 © 2019 ServiceNow, Inc. All Rights Reserved. Confidential. Deliver high-performing business services with visibility and AIOps Deliver business service health with AIOps Establish complete visibility across your operations estate CMDB Optimize spend on cloud usage and software
  • 14. Ironstream Integration with ServiceNow Discovery • Rapidly configure and launch secure discovery of IBM i and mainframe resources and their relationships • Auto-populate and maintain the ServiceNow Configuration Management Database (CMDB) • Automatically map dependencies & assign relationships • Get a single view of entire infrastructure to enable smarter IT decisions • Reduce decision times and errors, increase productivity with intelligent automation 14
  • 15. MID Server Agent Mainframe or IBM i LPAR Discovery Agent MID Server IMSMQ Db2 CICS Network Host Resources Probes sent to run discovery scripts Scripts execute commands Client runs command against agent Agent executes commands on LPAR Agent sends output back to client 1 2 3 4 5 6Sensor parses output and creates CIs Resources and Subsystems Discovery Workflow REXX VTAM MQ Commands MVS Db2 Queries Ironstream MCS
  • 16. Ironstream for ServiceNow Discovery • DB2 - DDF, DSG, databases, table spaces and deep configuration data • Completed jobs • DASD storage • Storage groups • CICS - regions, transactions, programs • IMS - regions, databases, transactions, programs • MQ - managers, channels, queues • Memory • LPAR • CPU • Network connectivity • Installed IBM/non-IBM software • Local Storage with ASPs • Memory • LPAR • CPU • Network connectivity • Installed software • Selected system values • Subsystems • Active jobs • Job queues • Output queues • Libraries • Program objects
  • 17. Ironstream Integration with ServiceNow Event Management • Extends cross-platform capabilities of ServiceNow ITOM to include mission-critical IBM mainframe & IBM i environments • Significantly reduces event noise and floods generated by third-party monitoring tools, • Monitor service health • Prevent outages • Easily take action • Sophisticated z/OS and IBM i event status management of any messages which go through the console to establish proactive enterprise systems management MAINFRAME 1 MAINFRAME 2
  • 18. MID Server Agent Mainframe or IBM i LPAR Ironstream MCS Event Mngmnt Agent MID Server JES, SDSF MQ Db2 CICS Network Host Resources Integrates with Event Management Passes to MID Server MCS filters & formats messages/information Agent detects messages, runs scripts, commands etc. on LPAR Agent sends output to client 5 4 3 1 2 6 Leverages workflow to process & automate Resources and Subsystems Event Management Workflow REXX VTAM NetView MVS TCP/IP
  • 19. Ironstream for ServiceNow Event Management • 110+ Event Rules including: • System Console/Syslog Events • CICS Transient Data Queue Events • IMS Master Terminal Operator Events • Interval Monitoring • SMS Group Threshold Monitoring • MQ Manager, Channels, Queues • Active Jobs • RMF based Performance Monitoring • Custom Message Interface • Message Automation • Reliable TCP Communication • Heartbeat and positive message acknowledgement • Message Buffering • Command Console • 170+ Rules for IBM i, including: • AS/400 State • ASP State • Audit Journal Alerts • Job Queue State • Job/Subsystem State • Memory Pool State • Threshold Monitoring • I/O per second • TIMW Status • Message Queue Alerts • MQ Series States • TCP Connection Status • CMTW Status • MTXW Status • Output Queue State • Services State • Agent Connection • Wait Status Monitoring
  • 24. Splunk: Industry-Leading Platform For Machine Data Online Services Web Services Servers Security GPS Location Storage Desktops Networks Packaged Application s Custom Apps Messagin g Telecoms Online Shopping Cart Web Clickstreams Databases Energy Meters Call Detail Records Smartphones and Devices RFID On-Premises Private Cloud Public Cloud Enterprise Scalability Universal Indexing Developer Platform Report & analyze Custom dashboards Monitor & alert Ad hoc search ! 24
  • 25. Comprehensive Security & Operational Metrics Disk Information • Reads/Writes • Disk Capacity • Disk Space Availability • Disk Busy • Disk Response Times Job Information • CPU used • Socket sends/receives • Stream file, directory & Symlink reads • Stream file writes • Seize/Wait time • Communication Puts/Gets CPU information Per Virtual CPU • Time used • Number of CPUs active TCP communications • Detailed stats at Datagram • Fragmentation information Physical Processor information per CPU • Time used • Owning Partition Virtual Processor information per Virtual CPU • Status, Time active, Time used. • Configured/Uncapped available time • Instruction count Memory pool information per Pool • Database faults • Non-database faults • Job transitions Size • Disk I/O stats • Pages aged and stolen Job summary information • CPU used • Disk I/O detail • Database/Non-database • Page faults • I/O Pending faults Security Information • User Profiles • System Values • Object attributes & authorities • Authorization Lists, Job Descriptions • Commands • Active Jobs, Spool Files • Changes to values, authorities, profiles, auth. lists • Access attempts (authentication or object access) • Sensitive object access
  • 26. Four Key Use Cases addressed with Ironstream and Splunk • Response times/SLAs • Latencies • Exceptions • Resource utilization • Sensitive data access & movement (PII/PHI) • Configuration settings (e.g. FISMA) • IRS Pub 1075 • PCI DSS • Incident triage • Anomalous behavior detection • Glass table view of entire service process • Predictive analytics • User Authentications • Account & login activity • FTP sessions & file activity Security Operational Intelligence IT Monitoring Compliance 26
  • 27. Precisely Ironstream for Splunk 360ᵒ View: • High performance, real-time collection of IBM mainframe information • Normalizes the z/OS data so it can be used by Splunk • Same Splunk dashboards, bigger, more complete data sets; free apps • Network managers, security analysts, application analysts, enterprise architects can use without requiring mainframe access or expertise 27
  • 28. What does Ironstream provide for Splunk? 28 • High performance, cost-effective platform for collecting critical log, machine, and event data • Normalization of mainframe and IBM i data for off-platform analytics & operations engines, including cloud • Completes the enterprise-wide picture of IT infrastructure • Better visibility • Better agility • Better control • Addresses the SME challenge: Used by network managers, security analysts, application analysts, enterprise architects without requiring detailed mainframe or IBM i access or expertise
  • 29. 29 Example Dashboards powered by Ironstream Security • Authorization Failures • Change Profile Events • System Value Changes • User Activities Operations • Capacity Monitoring • CPU Utilization • Create/Delete objects • Disk Performance • Job Durations • LPAR Performance • Message Queue Events • System Performance Application Data • Employee Database Use Case Splunk Dashboards
  • 30. Ironstream for Splunk works with Mainframe Data Precisely Ironstream Data Forwarder TCP/IP Ironstream Desktop DCE IDT Data Collection Extension Real-time Collection Assembler C, COBOL, REXX ! Data Sources HTTP(S) SMF RMF File Load Log4j IMSSYSLOG SYSLOGD System State SYSOUT Live SPOOL Db2 USS Alerts Network Components Forwarder API
  • 31. Ironstream for Splunk Splunk Enterprise IT Service Intelligence Powerful insights of your enterprise for IT Operations and Security with Ironstream for Splunk Precisely Ironstream integrates with the Splunk ITSI premium app to predict and prevent service degradation with a unified monitoring experience Enterprise Security Data Model for Mainframe Precisely Ironstream integrates with the Splunk Enterprise Security premium app to provide enterprise- wide view of security across all platforms The Precisely Ironstream Data Model provides a structured and logical view of mainframe log data elements in Splunk for faster searching, analysis and Splunk development
  • 34. Achieving a Single Source of Truth with Ironstream for ServiceNow Need for visibility across all IT infrastructure in ServiceNow – including mainframe • Rely on ServiceNow CMDB as “single source of truth” • No comprehensive coverage for mainframe 100’s business application touch mainframe • Mainframe key resource • No insight – constant demand on mainframe team • Manual integration • Too costly • Impossible to maintain • Out-of-date before complete Ironstream for ServiceNow • Certified ServiceNow solution • Simple install & configuration • Seamless integration with ServiceNow Discovery • Auto-populates & maintains CMDB • Auto-maps dependencies & relationships • Improved IT visibility • Complete, accurate, up-to-date CMDB • Visibility of all IT infrastructure • Visibility of relationships, connections & dependencies • Better agility • Improved service availability • Better change management • Significant reductions • People-hours • Related costs Challenge Solution Results
  • 35. Supporting optimal service delivery at U.S. based Loan Service Provider with Ironstream for Splunk O B J E C T I V E • To monitor mainframe IT operations to track health of service delivery for Loan Service Providers • Capture mainframe business data in support of system and application monitoring in Splunk C H A L L E N G E • Required several data feeds including SMF, SYSLOG and SYSOUT for batch job monitoring • Filtering the log data to selected jobs • Loading business data from sequential files S O L U T I O N • Precisely Ironstream forwarding required log data and filter it to specific messages and jobs • Splunk for IT operations analytics B E N E F I T • Increased visibility to support optimal service delivery for loan service providers • Fast time to value, with ease of installation and configuration, in contrast to competitive solutions
  • 36. European bank tackles PCI-DSS compliance with Ironstream for Splunk C H A L L E N G E • Working against a tight deadline to build a solution with Splunk to continuously monitor all relevant PCI DSS requirements. • Needed a proven, easy-to-use solution to include their busy, complex mainframe environment, which included 6 mainframes and 900+ production CICS regions S O L U T I O N • Ironstream for Splunk: • Seamless integration to include mainframe log data into Splunk • Proven to be easier to install, configure and use vs. competition B E N E F I T • Compliance with PCI DSS mandates • Single, enterprise-wide monitoring solution for all systems, including mainframe

Editor's Notes

  • #4: There’s the added dimension that outages and service degradations are more public than ever before. There are monitoring agencies and web sites dedicated to tracking downtime…
  • #5: And, beyond that – not only is everybody watching, but as soon as something goes wrong, everyone is sharing it. Here we have social media posts about some recent, high-profile outages at Costco and Ticketmaster. Costco had a real hard time over Black Friday 2019 – one of the most important days of the year for a retailer – where their online shopping went down. It was down for 16 hours! It costs them $11 million dollars – and that’s just from lost revenue. On top of that, their failings were shared across social media. And all of this because of an internal server error – if you can’t read the message, it says “The server encountered an internal error or misconfiguration and was unable to complete your request.” I wouldn’t want to be the IT manager responsible for that server, would you? The more your business relies on digital, and the higher your customer expectations, the worse an outage can be. For example, Ticketmaster users were extremely animated voicing their displeasure online when trying to buy tickets to a sporting event and there was a system error. So – in short – our customers need to have the power to prevent outages before they happen – and when that’s not possible, they need to identify and fix them as soon as possible, to limit the negative impact to the business.
  • #8: So it is vital that organizations get a good grip on what is occurring across their I.T. landscape. However, IT today is extremely complex, with systems that are both interconnected to deliver services, yet silo’d from a management, security and tools perspective. This stands in the way of the awareness, agility and availability that’s required. And those silo’d tools are very much the problem when it comes to mainframes and IBM i systems because platforms like Splunk don’t natively integrate with them – but they are critically important. This slide here actually shows you part of a real network – and it came from one of our customers. There are a lot of moving parts in here. It is complex. It has to be available. It has to be reliable. To ensure this, the customer needs visibility into what's going on. So what is happening in that big black box at the bottom, that which happens to be the mainframe – but could have also been IBM i.   You can see that it’s a major component in some critical systems. And they need to see what is going on inside that box. Without a tool like Ironstream, they're really going to struggle to tap into that and see what's going on in there – in their mainframe or IBM I -- alongside all the other moving parts and pieces across the infrastructure. And that’s the visibility that Ironstream provides.
  • #9: Today’s leading modern platforms do an excellent job for distributed and cloud environments
  • #10: Assure Monitoring and Reporting
  • #14: At ServiceNow, our core principle is straight forward. ServiceNow makes work, work better for people. Transform old, manual ways of working into modern digital workflows, so employees and customers get what they need, when they need it—fast, simple, easy. A key component is delivering high-performance business services with visibility and AIOps. While I just covered some of the major challenges, ServiceNow helps establish visibility, deliver healthy services, and optimize spend. For visibility, the key is establishing a complete, current, and accurate view of resources and assets across your entire operations estate and provide service-aware context for your most important apps and services. For health, delivering high-performance business services requires a complete understanding across the organization by leveraging AIOps to help identify, isolate, and resolve business-impacting issues. For optimization, eliminating manual processes with automation empowers IT teams and organizations to get a handle on the exploding growth of cloud and software spend and reduce the impact of planned and unplanned audits. ServiceNow helps achieve these goals with our IT Operations Management and Software Asset Management capabilities.
  • #15: The combination of Ironstream and ServiceNow enables enterprises to auto-populate and maintain the Configuration Management Database (CMDB) with all major IBM mainframe and IBM i Configuration Items (CIs) and their relationships.
  • #16: Alors, comment fait Ironstream ? Un agent sur le mainframe ou l’IBMi utilise des sondes et des capteurs pour découvrir les composants. Ceux-ci sont communiqués au ServiceNow MID server, qui à son tour envoie les informations à ServiceNow fonctionnant dans le Cloud où les items de configuration du mainframe et IBMi apparaissent dans les écrans et les tableaux de bord de ServiceNow. Tout cela peut fonctionner en mains libres, de manière automatisée et programmée. Vous obtenez ainsi une vue précise et actualisée de votre mainframe et de votre paysage IBMI. Très simple et efficace.
  • #19: Turning to Event Management…
  • #28: High performance, low-cost, platform for collecting critical system information in real-time Normalization of the z/OS and IBM i data so it can be used by off platform analytics engines Full analytics, visualization, and customization with no limitations on what can be viewed Ability to easily combine information from different data sources and systems Address the SME challenge: use by network managers, security analysts, application analysts, enterprise architects without requiring mainframe access or expertise
  • #31: The SMF and log data on your mainframe holds the key to true insights about your complete enterprise, but if this machine data stays silo’d within your mainframe team, you’re essentially flying half-blind. Include ALL the relevant data for Splunk to correlate, and for you to analyze, in your Splunk Enterprise, Splunk Enterprise Security and/or Splunk IT Service Intelligence.
  • #36: A key player in the U.S. secondary mortgage market where they buy loans from approved lenders. They had been using Splunk to monitor the health of their critical applications but their IBM mainframe data was not being included, creating a blind spot in tracking the health of their service delivery for their Loan Service Provider customers. After implementing Ironstream, they have integrated the mainframe data with the other important system data in Splunk and now have a comprehensive, end-to-end view of their application and system health.