SlideShare a Scribd company logo
Government Agencies Using Splunk:
Is Your Critical Data Missing?
Bill Hammond, Product Marketing
John de Saint Phalle, Sales Engineering
Mainframes &
IBM i servers
adapt and deliver
increasing value
with each new
technology wave
91%of executives predict long-term
viability of the mainframe as the
platform continues evolving to
meet digital business demands
>100kcompanies today use IBM i
technology to run significant
workloads & power critical
business applications
BMC 12th Annual Mainframe Research Results – Nov. 2017 Syncsort 2018 State of Resilience: The New IT Landscape for Executives:
Threats, Opportunities and Best Practices.” Jan. 2018
that’s 2,500,000,000 -- business
transactions per mainframe per day
2000+ organizations overall
2.5 B
Market
Landscape and
Key Concepts:
Data Analytics
Challenges
So many data sources
Mainframe:
Systems Management Facility (SMF),
Syslog, Log4j web and application logs,
RMF, RACF, USS files and standard
datasets
IBM i:
QAUD Journal, QHIST, Message Queues,
Database Journals
Format of data
Mainframe:
• Complex data structures (SMF) with
headers, product sections, data
sections, variable length and self-
describing
• EBCDIC not recognized outside of
the mainframe world
• Binary flags and fields
IBM i:
• Complex data structures with
unique journal entry types, headers,
product sections, data sections,
variable length and self-describing
• IBM i journals are held in DB2
• Performance Collection Services
• IBM i information needs to be
converted to workable formats
such as JSON, Syslog, CEF etc.
Volume of data
Millions of log records generated daily
• 9.7TB Average Daily Mainframe Log Data
Difficulty to get the
information in a timely
manner
• Not real-time, typically have to wait
overnight for an offload
• Typical daily FTP upload/downloads
can’t get granular
Ironstream
Ironstream = One Product
Ironstream Solutions
Application/System Monitoring
• Monitor operational status of enterprise IT infrastructure
• Make better decisions to take control of the IT infrastructure
• Monitor Resource utilization and availability
• Problem Detection & Isolation
• Ensure SLAs are met
• Reduce MTTI, MTTR
• System Health Monitoring with Splunk IT Service Intelligence
Security and Compliance
• Detect and prevent security threats
• Privileged activity
• Ensure compliance
• Ensure audits pass
• Enterprise Security Monitoring with Splunk ES
• High performance, low-cost, platform for collecting critical
system information in real-time
• Normalization of the z/OS and IBM i data so it can be used by off
platform analytics engines
• Full analytics, visualization, and customization with no limitations
on what can be viewed
• Ability to easily combine information from different data sources
and systems
• Address the SME challenge: use by network managers, security
analysts, application analysts, enterprise architects without
requiring mainframe access or expertise
What does Ironstream® deliver?
Syncsort
Ironstream for
IBM z and IBM i
• Enabling organizations to get
machine data from System z and
IBM i to Splunk for log analytics.
• Extend What Splunk Does
Already, to the Other ~40%-80%
of IT Processing
• 360ᵒ Degree View: Make the
Splunk View of the Enterprise
Complete
• Same Splunk Dashboards, Bigger,
More Complete Data Sets; Free
Apps
Why Ironstream
Less Complexity
Collect mainframe and IBM i data;
correlate with data from other
platforms; no legacy system expertise
required
Clearer Security Information
Identify unauthorized mainframe and
IBM i server access, other security
risks; prepares and visualizes key
data for compliance audits
Healthier IT Operations
Real-time alerts identify problems in
all key environments View latency,
transactions per second, exceptions,
etc.
Effective Problem-Resolution
Management
Real-time views to identify real or
potential failures earlier; view related
'surrounding' information to support
triage repair or prevention
Higher Operational Efficiency
Enhanced event correlation across
systems; Staff resolves problems faster;
“do more with less”
Eliminate Your Mainframe and
IBM i “Blind-Spots”
Splunk/Elastic + Ironstream = Your
360ᵒ Enterprise View
Ironstream Demo
Ironstream
Customers
Federal Agency
Meets Audit &
Information Security
Requirements with
Syncsort Ironstream
Challenge:
Needed to collect and analyze
operational log data from all of its
many IT systems to meet ever-
changing compliance requirements.
The agency was (and is) using Splunk
Enterprise but was missing critical
Mainframe log data including:
• Extremely sensitive
authentication information
• Enterprise-wide details on
password changes, log-in
successes and failures
• Accounts being locked out of the
mainframe systems.
Results:
With Syncsort Ironstream they have
real-time enterprise-wide visibility
into the most sensitive authentication
procedures and data across their IT
environment:
The agency is now able to audit for
unusual activity at the individual user
levels, helping them detect security
exposures such as:
• Access from an unusual location,
unusual network zone, or unusual
time of day.
• Changes to user privileges and
rights.
• Excessive data transmissions.
• Unusual movement of data.
Q&A
Government Agencies Using Splunk: Is Your Critical Data Missing?

More Related Content

PDF
From the Splunk Front Lines: Unlocking Insights from IBM i Data
PPTX
Alan weber semicon_integrated_equipment_data_collection_smart_manufacturing
PPTX
Smart Manufacturing Requirements for Equipment Capability and Control
PDF
Get Mainframe Visibility to Enhance SIEM Efforts in Splunk
PPT
informatica data replication (IDR)
PDF
AMB110: IT Asset Management – How to Start When You Don’t Know Where to Start
PPTX
Case study: Leading legal services firm deploys Applications Manager across m...
PDF
Gartner_Critical Capabilities for SIEM 9.21.15
From the Splunk Front Lines: Unlocking Insights from IBM i Data
Alan weber semicon_integrated_equipment_data_collection_smart_manufacturing
Smart Manufacturing Requirements for Equipment Capability and Control
Get Mainframe Visibility to Enhance SIEM Efforts in Splunk
informatica data replication (IDR)
AMB110: IT Asset Management – How to Start When You Don’t Know Where to Start
Case study: Leading legal services firm deploys Applications Manager across m...
Gartner_Critical Capabilities for SIEM 9.21.15

What's hot (20)

PDF
Roi-based Data Collection by Alan Weber at Cimetrix
PDF
Enterprise Service Manager (ESM) : data sheet1
ODP
ERP 101 By Open Source ERP Guru
PDF
FlexNet Manager Suite Cloud
PPTX
Operational Intelligence Using Hadoop
PPTX
Connectivity challenges APC Europe by Alan Weber
PPTX
IT Security: Eliminating threats with effective network & log analysis
PPTX
Telecom provider germany ncm casestudy
PPTX
ILINX Capture Connect Share Part One
PPT
Remote Infrastructure Management
PPTX
Addressing Connectivity Challenges of Disparate Data Sources in Smart Manufac...
PPTX
Smarter Manufacturing with SEMI Standards: Practical Approaches for Plug-and-...
PPTX
Hi600 u08_inst_slides
PPTX
The Power E164: EDA Common Metadata
PDF
Forklift Usage Reports, SkidWeigh Series, 2 p v2
PPTX
Smarter Manufacturing through Equipment Data-Driven Application Design
PDF
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
PPTX
Overcoming Barriers to the Cloud
PDF
From Disaster to Recovery: Preparing Your IT for the Unexpected
PPTX
Chmura nieuchronnym elementem Twojego IT w (nie)dalekiej przyszłości. Śmierte...
Roi-based Data Collection by Alan Weber at Cimetrix
Enterprise Service Manager (ESM) : data sheet1
ERP 101 By Open Source ERP Guru
FlexNet Manager Suite Cloud
Operational Intelligence Using Hadoop
Connectivity challenges APC Europe by Alan Weber
IT Security: Eliminating threats with effective network & log analysis
Telecom provider germany ncm casestudy
ILINX Capture Connect Share Part One
Remote Infrastructure Management
Addressing Connectivity Challenges of Disparate Data Sources in Smart Manufac...
Smarter Manufacturing with SEMI Standards: Practical Approaches for Plug-and-...
Hi600 u08_inst_slides
The Power E164: EDA Common Metadata
Forklift Usage Reports, SkidWeigh Series, 2 p v2
Smarter Manufacturing through Equipment Data-Driven Application Design
Case Study: Datotel Extended the Power of Infrastructure Management to the Ph...
Overcoming Barriers to the Cloud
From Disaster to Recovery: Preparing Your IT for the Unexpected
Chmura nieuchronnym elementem Twojego IT w (nie)dalekiej przyszłości. Śmierte...
Ad

Similar to Government Agencies Using Splunk: Is Your Critical Data Missing? (20)

PDF
Ironstream for IBM i - Enabling Splunk Insight into Key Security and Operatio...
PPTX
What Does Artificial Intelligence Have to Do with IT Operations?
PPTX
Don't Leave Your Traditional IBM Systems Out of Your IT Operations Efforts
PPTX
Downtime is Not an Option: Integrating IBM Z into ServiceNow and Splunk
PDF
360-Degree View of IT Infrastructure with IT Operations Analytics
PPTX
Why Integrating IBM Z into ServiceNow and Splunk Is So Important
PDF
NZS-4532 - Bringing Historical Data to Life with IBMs SMF Data Engine
PDF
Old Dogs, New Tricks: Big Data from and for Mainframe IT
PDF
Digital Transformation: How to Run Best-in-Class IT Operations in a World of ...
PPTX
Improve IT Security and Compliance with Mainframe Data in Splunk
PPTX
IBM i Security: Identifying the Events That Matter Most
PPTX
Effective Security Monitoring for IBM i: What You Need to Know
PDF
IBM IT Operations Analytics for z systems
PDF
IBM IT Operations Analytics for z Systems
PPTX
IBM i Security SIEM Integration
PPTX
IBM i HA and Security: Why They Need to Work Together
PPTX
Integrating IBM Z and IBM i Operational Intelligence Into Splunk, Elastic, an...
PDF
NZS-4555 - IT Analytics Keynote - IT Analytics for the Enterprise
PPTX
ee it All, Secure it All: How SIEM Strengthens Your Business
PDF
EMA Presentation: Driving Business Value with Continuous Operational Intellig...
Ironstream for IBM i - Enabling Splunk Insight into Key Security and Operatio...
What Does Artificial Intelligence Have to Do with IT Operations?
Don't Leave Your Traditional IBM Systems Out of Your IT Operations Efforts
Downtime is Not an Option: Integrating IBM Z into ServiceNow and Splunk
360-Degree View of IT Infrastructure with IT Operations Analytics
Why Integrating IBM Z into ServiceNow and Splunk Is So Important
NZS-4532 - Bringing Historical Data to Life with IBMs SMF Data Engine
Old Dogs, New Tricks: Big Data from and for Mainframe IT
Digital Transformation: How to Run Best-in-Class IT Operations in a World of ...
Improve IT Security and Compliance with Mainframe Data in Splunk
IBM i Security: Identifying the Events That Matter Most
Effective Security Monitoring for IBM i: What You Need to Know
IBM IT Operations Analytics for z systems
IBM IT Operations Analytics for z Systems
IBM i Security SIEM Integration
IBM i HA and Security: Why They Need to Work Together
Integrating IBM Z and IBM i Operational Intelligence Into Splunk, Elastic, an...
NZS-4555 - IT Analytics Keynote - IT Analytics for the Enterprise
ee it All, Secure it All: How SIEM Strengthens Your Business
EMA Presentation: Driving Business Value with Continuous Operational Intellig...
Ad

More from Precisely (20)

PDF
The Future of Automation: AI, APIs, and Cloud Modernization.pdf
PDF
Unlock new opportunities with location data.pdf
PDF
Reimagining Insurance: Connected Data for Confident Decisions.pdf
PDF
Introducing Syncsort™ Storage Management.pdf
PDF
Enable Enterprise-Ready Security on IBM i Systems.pdf
PDF
A Day in the Life of Location Data - Turning Where into How.pdf
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
PDF
Solving the CIO’s Dilemma: Speed, Scale, and Smarter SAP Modernization.pdf
PDF
Solving the Data Disconnect: Why Success Hinges on Pre-Linked Data.pdf
PDF
Cooking Up Clean Addresses - 3 Ways to Whip Messy Data into Shape.pdf
PDF
Building Confidence in AI & Analytics with High-Integrity Location Data.pdf
PDF
SAP Modernization Strategies for a Successful S/4HANA Journey.pdf
PDF
Precisely Demo Showcase: Powering ServiceNow Discovery with Precisely Ironstr...
PDF
The 2025 Guide on What's Next for Automation.pdf
PDF
Outdated Tech, Invisible Expenses – How Data Silos Undermine Operational Effi...
PDF
Modernización de SAP: Maximizando el Valor de su Migración a SAP S/4HANA.pdf
PDF
Outdated Tech, Invisible Expenses – The Hidden Cost of Disconnected Data Syst...
PDF
Migration vers SAP S/4HANA: Un levier stratégique pour votre transformation d...
PDF
Outdated Tech, Invisible Expenses: The Hidden Cost of Poor Data Integration o...
PDF
The Changing Compliance Landscape in 2025.pdf
The Future of Automation: AI, APIs, and Cloud Modernization.pdf
Unlock new opportunities with location data.pdf
Reimagining Insurance: Connected Data for Confident Decisions.pdf
Introducing Syncsort™ Storage Management.pdf
Enable Enterprise-Ready Security on IBM i Systems.pdf
A Day in the Life of Location Data - Turning Where into How.pdf
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Solving the CIO’s Dilemma: Speed, Scale, and Smarter SAP Modernization.pdf
Solving the Data Disconnect: Why Success Hinges on Pre-Linked Data.pdf
Cooking Up Clean Addresses - 3 Ways to Whip Messy Data into Shape.pdf
Building Confidence in AI & Analytics with High-Integrity Location Data.pdf
SAP Modernization Strategies for a Successful S/4HANA Journey.pdf
Precisely Demo Showcase: Powering ServiceNow Discovery with Precisely Ironstr...
The 2025 Guide on What's Next for Automation.pdf
Outdated Tech, Invisible Expenses – How Data Silos Undermine Operational Effi...
Modernización de SAP: Maximizando el Valor de su Migración a SAP S/4HANA.pdf
Outdated Tech, Invisible Expenses – The Hidden Cost of Disconnected Data Syst...
Migration vers SAP S/4HANA: Un levier stratégique pour votre transformation d...
Outdated Tech, Invisible Expenses: The Hidden Cost of Poor Data Integration o...
The Changing Compliance Landscape in 2025.pdf

Recently uploaded (20)

PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Machine learning based COVID-19 study performance prediction
PDF
KodekX | Application Modernization Development
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Cloud computing and distributed systems.
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Machine learning based COVID-19 study performance prediction
KodekX | Application Modernization Development
Agricultural_Statistics_at_a_Glance_2022_0.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Diabetes mellitus diagnosis method based random forest with bat algorithm
NewMind AI Monthly Chronicles - July 2025
Spectral efficient network and resource selection model in 5G networks
Understanding_Digital_Forensics_Presentation.pptx
Network Security Unit 5.pdf for BCA BBA.
Unlocking AI with Model Context Protocol (MCP)
Cloud computing and distributed systems.
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Advanced methodologies resolving dimensionality complications for autism neur...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...

Government Agencies Using Splunk: Is Your Critical Data Missing?

  • 1. Government Agencies Using Splunk: Is Your Critical Data Missing? Bill Hammond, Product Marketing John de Saint Phalle, Sales Engineering
  • 2. Mainframes & IBM i servers adapt and deliver increasing value with each new technology wave 91%of executives predict long-term viability of the mainframe as the platform continues evolving to meet digital business demands >100kcompanies today use IBM i technology to run significant workloads & power critical business applications BMC 12th Annual Mainframe Research Results – Nov. 2017 Syncsort 2018 State of Resilience: The New IT Landscape for Executives: Threats, Opportunities and Best Practices.” Jan. 2018 that’s 2,500,000,000 -- business transactions per mainframe per day 2000+ organizations overall 2.5 B
  • 3. Market Landscape and Key Concepts: Data Analytics Challenges So many data sources Mainframe: Systems Management Facility (SMF), Syslog, Log4j web and application logs, RMF, RACF, USS files and standard datasets IBM i: QAUD Journal, QHIST, Message Queues, Database Journals Format of data Mainframe: • Complex data structures (SMF) with headers, product sections, data sections, variable length and self- describing • EBCDIC not recognized outside of the mainframe world • Binary flags and fields IBM i: • Complex data structures with unique journal entry types, headers, product sections, data sections, variable length and self-describing • IBM i journals are held in DB2 • Performance Collection Services • IBM i information needs to be converted to workable formats such as JSON, Syslog, CEF etc. Volume of data Millions of log records generated daily • 9.7TB Average Daily Mainframe Log Data Difficulty to get the information in a timely manner • Not real-time, typically have to wait overnight for an offload • Typical daily FTP upload/downloads can’t get granular
  • 6. Ironstream Solutions Application/System Monitoring • Monitor operational status of enterprise IT infrastructure • Make better decisions to take control of the IT infrastructure • Monitor Resource utilization and availability • Problem Detection & Isolation • Ensure SLAs are met • Reduce MTTI, MTTR • System Health Monitoring with Splunk IT Service Intelligence Security and Compliance • Detect and prevent security threats • Privileged activity • Ensure compliance • Ensure audits pass • Enterprise Security Monitoring with Splunk ES
  • 7. • High performance, low-cost, platform for collecting critical system information in real-time • Normalization of the z/OS and IBM i data so it can be used by off platform analytics engines • Full analytics, visualization, and customization with no limitations on what can be viewed • Ability to easily combine information from different data sources and systems • Address the SME challenge: use by network managers, security analysts, application analysts, enterprise architects without requiring mainframe access or expertise What does Ironstream® deliver?
  • 8. Syncsort Ironstream for IBM z and IBM i • Enabling organizations to get machine data from System z and IBM i to Splunk for log analytics. • Extend What Splunk Does Already, to the Other ~40%-80% of IT Processing • 360ᵒ Degree View: Make the Splunk View of the Enterprise Complete • Same Splunk Dashboards, Bigger, More Complete Data Sets; Free Apps
  • 9. Why Ironstream Less Complexity Collect mainframe and IBM i data; correlate with data from other platforms; no legacy system expertise required Clearer Security Information Identify unauthorized mainframe and IBM i server access, other security risks; prepares and visualizes key data for compliance audits Healthier IT Operations Real-time alerts identify problems in all key environments View latency, transactions per second, exceptions, etc. Effective Problem-Resolution Management Real-time views to identify real or potential failures earlier; view related 'surrounding' information to support triage repair or prevention Higher Operational Efficiency Enhanced event correlation across systems; Staff resolves problems faster; “do more with less” Eliminate Your Mainframe and IBM i “Blind-Spots” Splunk/Elastic + Ironstream = Your 360ᵒ Enterprise View
  • 12. Federal Agency Meets Audit & Information Security Requirements with Syncsort Ironstream Challenge: Needed to collect and analyze operational log data from all of its many IT systems to meet ever- changing compliance requirements. The agency was (and is) using Splunk Enterprise but was missing critical Mainframe log data including: • Extremely sensitive authentication information • Enterprise-wide details on password changes, log-in successes and failures • Accounts being locked out of the mainframe systems. Results: With Syncsort Ironstream they have real-time enterprise-wide visibility into the most sensitive authentication procedures and data across their IT environment: The agency is now able to audit for unusual activity at the individual user levels, helping them detect security exposures such as: • Access from an unusual location, unusual network zone, or unusual time of day. • Changes to user privileges and rights. • Excessive data transmissions. • Unusual movement of data.
  • 13. Q&A