Easily Add z/OS Events to any SIEM
Although mainframes produce plenty of information about what’s happening (event log, audit log, syslog, etc.), you need a way to quickly and easily separate critical security incidents from business-as-usual events – and send them in the right format to your enterprise SIEM.
VitalSigns SIEM Agent for z/OS (VSA, formerly SMA_RT) forwards filtered mainframe security logs and messages (from RACF, ACF2, Top Secret, DB2, CICS, FTP, etc.) in the proper format, to Security Information and Event Management (SIEM) systems such as Splunk®, AlienVault, LogRhythm NextGen SIEM, IBM® QRadar®, ArcSight, and others. Mainframe teams must comply with strict audit policies but may not have the time or the resources to filter and format the right data and send it to the enterprise SIEM. Let VSA help.
VSA brings your z/OS mainframe into the center of your enterprise security infrastructure without hassle and in real time.
VSA is an invaluable tool to help your business comply with FISMA, GDPR, GLBA, HIPAA, PCI, SOX, and other standards. Administrators can define specific parameters to monitor with more detail and at greater depth, and automatically send data to any enterprise SIEM.
With VSA monitoring the mainframes, your security team has a central, enterprise-wide view of all the events they need to capture and all the security threats they need to recognize.
Mainframe security no longer needs to depend on batch jobs running long after any incident. Events are tracked and uncovered in real time, from all corners of the business.
This z/OS SIEM solution is flexible enough to integrate with any distributed SIEM product and is certified for CEF and LEEF formats. VSA is a Ready for IBM Security Intelligence product. If you need to provide mainframe data to your SIEM solution (e.g., Splunk, AlienVault, LogRhythm NextGen SIEM, ArcSight, QRadar, McAfee® Enterprise Security Manager), VSA is worth your consideration.
- Delivers mainframe data to all conventional SIEM products
- Certified for CEF and LEEF formats
- Connects with standard z/OS security products
- Workload is zIIP eligible; See VSA 4.3 Benchmark Tests
- Monitors z/OS and UNIX System Services (USS)
- Gathers intelligence from z/OS SMF and the system operator interface
- Uses both signature- and anomaly-based attack detection
- Provides real-time alerts that can be managed, filtered, routed, and searched via SIEM software
- APIs allow for defining and filtering TSO, CICS, and batch events
- Easy installation does not require z/OS IPLs
- A small footprint in each LPAR, with little CPU overhead
Attacks continue to increase in complexity and sheer volume. Every company stands the chance of being hacked.
VSA gives you the central, end-to-end systems visibility you need to help stay in control of your organization’s data security. Because the truth is, your business is about to be compromised… or it already has been.
DBTA Trend-Setting Products List
VSA was chosen as one of the top 100 Trend-Setting Products by DBTA. We’re thrilled to be included in this prestigious list.
Read the VSA Product Spotlight that was included in this DBTA edition.
Understanding Potential Savings with zIIP Offload and VitalSigns SIEM Agent for z/OS 4.3
This 30-minute webinar is available for you to watch right now. We’d love to hear from you with any questions you may have!
z/OS Security & Compliance Software
Check out the latest SDS mainframe security software solutions. These popular products also offer relevant and significant compliance assistance on z/OS.