Product - SMF2ELK

SMF Realtime Data Feed to Elastic Search

Functionality

SMD2ELK can read SMF data directly in realtime from the logstream. Of course this SMF data can also be read from an SMF Unload Dataset.

This data is then split into individual fields, enriched with master data and then written directly to Elastic Search via a web service. During this process, over 1000 additional fields are also calculated from the raw data (e.g. CPU usage in %).

After a delay of about 5 seconds, the data is available in Elastic Search and can be analyzed via Kibana.

 Data quality

To ensure that the data is never written twice in Elastic Search we have programmed a sophisticated mechanism. This mechanism runs completely automatically and does not require any further programming or definitions from the user side. If, for example, a processing step breaks off, it can simply be restarted at the start of the dataset.

 

The following SMF records are supportedt

  • 0, 2, 3, 6, 7
  • 14, 15, 17, 18 Dataset Activity
  • 21, 26,
  • 30 Job Activity
  • 42, 50, 61, 65, 66
  • 70, 71, 72, 73, 74, 75, 77, 78 RMF und WLM
  • 88, 89
  • 100, 101, 102 DB2
  • 110 CICS
  • 115, 116 MQ
  • 113

In total, these are over 17000 fields.

z/OS Features of SMF2ELK

  • 99% zAAP Enabled Workload
  • native BSAM access für z/OS Dataset, z.B. VBS Dataset
  • Monitor Service runs as STC
  • z/OS Operator Command support

IBM, the IBM logo, IBM Cloud, IBM z16, IBM Z, Telum and z/OS are trademarks or registered trademarks of International Business Machines Corporation, in the United States and/or other countries.