Anyone ever tried to point splunk at a mainframe SMF records (RACF)?
Is it possible? How do you do it?
Cheers,
G.
The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Previous Topic: Splunk Crashes on Start | Next Topic: Moving Windows 2003 syslogs to splunk server
Anyone ever tried to point splunk at a mainframe SMF records (RACF)?
Is it possible? How do you do it?
Cheers,
G.
Hi
I've done some work with CA/TSS. You will most probably have to write a report to extract what you want and feed Splunk. In my case it was a combination of remote calls via DSI and custom reports that were FTP'ed to the Indexer. I then massage the data before indexing.
Marinus