Easily Add z/OS Events to any SIEM
Although mainframes produce plenty of information about what’s happening (event log, audit log, syslog, etc.), you need a way to quickly and easily separate critical security incidents from business-as-usual events – and send them in the right format to your enterprise SIEM.
VitalSigns SIEM Agent for z/OS (VSA, formerly SMA_RT) forwards filtered mainframe security logs and messages (from RACF, ACF2, Top Secret, DB2, CICS, FTP, etc.) in the proper format, to Security Information and Event Management (SIEM) systems such as Splunk®, AlienVault, LogRhythm NextGen SIEM, IBM® QRadar®, ArcSight, and others. Mainframe teams must comply with strict audit policies but may not have the time or the resources to filter and format the right data and send it to the enterprise SIEM. Let VSA help.
VSA brings your z/OS mainframe into the center of your enterprise security infrastructure without hassle and in real time.
Compliance
VSA is an invaluable tool to help your business comply with FISMA, GDPR, GLBA, HIPAA, PCI, SOX, and other standards. Administrators can define specific parameters to monitor with more detail and at greater depth, and automatically send data to any enterprise SIEM.
Security
With VSA monitoring the mainframes, your security team has a central, enterprise-wide view of all the events they need to capture and all the security threats they need to recognize.
Transparency
Mainframe security no longer needs to depend on batch jobs running long after any incident. Events are tracked and uncovered in real time, from all corners of the business.
This z/OS SIEM solution is flexible enough to integrate with any distributed SIEM product and is certified for CEF and LEEF formats. VSA is a Ready for IBM Security Intelligence product. If you need to provide mainframe data to your SIEM solution (e.g., Splunk, AlienVault, LogRhythm NextGen SIEM, ArcSight, QRadar, McAfee® Enterprise Security Manager), VSA is worth your consideration.
Features
- Delivers mainframe data to all conventional SIEM products
- Certified for CEF and LEEF formats
- Connects with standard z/OS security products
- Workload is zIIP eligible; See VSA 4.3 Benchmark Tests
- Monitors z/OS and UNIX System Services (USS)
- Gathers intelligence from z/OS SMF and the system operator interface
- Uses both signature- and anomaly-based attack detection
- Provides real-time alerts that can be managed, filtered, routed, and searched via SIEM software
- APIs allow for defining and filtering TSO, CICS, and batch events
- Easy installation does not require z/OS IPLs
- A small footprint in each LPAR, with little CPU overhead
Datasheet
White Paper
Resources
Request Info
Attacks continue to increase in complexity and sheer volume. Every company stands the chance of being hacked.
VSA gives you the central, end-to-end systems visibility you need to help stay in control of your organization’s data security. Because the truth is, your business is about to be compromised… or it already has been.
DBTA Trend-Setting Products List
VSA was chosen as one of the top 100 Trend-Setting Products by DBTA. We’re thrilled to be included in this prestigious list.
Read the VSA Product Spotlight that was included in this DBTA edition.
If your browser failed to open the short videos tab within the VSA Webinar page, please click here.
If your browser failed to open the VSA Webinar page, please click here.
If your browser failed to open the VSA Datasheet (opens in a new tab usually), please click here.
If your browser failed to open the VSA Resources page, please click here.
Product Webinar
Preparing for Mainframe Security Vulnerabilities
Reg Harbeck and Colin van der Ross engage in a back-and-forth discussion centered on mainframe security vulnerabilities. They discuss what to prepare against and how to protect your organization. This webinar is hosted by TechChannel.
More Solutions
z/OS Security & Compliance Software
Check out the latest SDS mainframe security software solutions. These popular products also offer relevant and significant compliance assistance on z/OS.
Free Demo/Trial
We offer individualized product demonstrations by request. Your organization can also try SDS Software on your system for 30 days, free of charge.