https://www.ibm.com/docs/en/szs/3.2.0?topic=alerts-accessread-site-sensitive-data-set-1212
Original Message:
Sent: 08/28/26 05:24 PM
From: Radosław Skorupka
Subject: zSecure Alert & Sensitive Resources puzzle
Yet antoher update:
It seems I solved the puzzle.
I checked again audit setttings for the dataset profiles covering both "sensitiv" datasets.
SYS1....SENSITIVE has AUDIT(ALL(READ)) !
So, I set same setting for ZSECUR....SENSITIV and now it works.
Is it undocumented or I missed relevant section again?
Last but not least: THANK YOU for the help!
Regards
------------------------------
Radosław Skorupka
------------------------------
Original Message:
Sent: 08/28/26 04:52 PM
From: Radosław Skorupka
Subject: zSecure Alert & Sensitive Resources puzzle
Update:
I created zSecure Alert definition from scratch:
Empty C2PCUST library (only C2PXPARM (empty member), C2POLALC (from SKCRSAMP), C2PEMFRT (allocation for Extended Monitor snapshot CKREEZE's)
I have even cleared my ISPF profile - deleted zSecure-related members.
Then I created whole configuration from scratch by reading panels from other system and typing it manually.
Same set of alerts, same mail file content, same fields on first panel (B).
Restarted C2POLICE with new PPARM.
Then edited SENSRSRC member using SE.A.S panel. Then refreshed configuration.
And... still the same problem! That means touching SYS1....SENSITIV causes alert, but teaching ZSECUR....SENSITIV is ignored.
Regards
------------------------------
Radosław Skorupka
------------------------------
Original Message:
Sent: 08/28/26 03:45 PM
From: Radosław Skorupka
Subject: zSecure Alert & Sensitive Resources puzzle
Well, actually it is none of the alerts selected/configure via S action character.
I mean the following:

In other words: zSecure ISPF panels, option SE.A.S
First entry on the list means SENSRSRC member edit. When updated, a message appers saying I need to perform Refresh.
The content of the SENSRSRC is straightforward:

(note, both pictures are taken from Alert manual, page 27)
note2: no other SENS* members were customized
no custom-defined alerts. Just bunch of predefined alerts are selected. I can provide the list, but I believe there is nothing related to the issue there.
Regards
------------------------------
Radosław Skorupka
------------------------------
Original Message:
Sent: 08/28/26 03:25 PM
From: Jeroen Tiggelman
Subject: zSecure Alert & Sensitive Resources puzzle
Hi Radoslaw,
It might be easier to understand your scenario if you explained which alert you were talking about.
Most alerts are SMF-based, including ones that are for sensitive data sets, but not all.
Regards,
------------------------------
Jeroen Tiggelman
IBM - Software Development Manager IBM zSecure
Delft
------------------------------
Original Message:
Sent: 08/28/26 03:01 PM
From: Radosław Skorupka
Subject: zSecure Alert & Sensitive Resources puzzle
Hi Jeroen,
I have to admit I don't understand the relationship to SMF.
Let me explain my setup again:
There is hlq.some.C2PCUST library
There is a member SENSRSRC
The content looks like the following:
SIMULATE CLASS=DATASET ACCESS=READ,
SENSITIVITY=Site-Dsn-R,
RESOURCE=SYS1.ZSE.SENSITIV.RESOURCE
SIMULATE CLASS=DATASET ACCESS=READ,
SENSITIVITY=Site-Dsn-R,
RESOURCE=ZSECUR.DATA.SENSITIV.RESOURCE
Both datasets are protected with generic RACFprofiles like ZSECUR.** and SYS1.ZSE.**
Userid accessing the datasets has ALTER to both profiles.
SMF settings are quite typical, RACF records are being collected, however both profiles mentioned above have AUDIT(FAILURE(READ)) setting (which is default) and there are no SMF80 records cut in that scenario.
However when I touch SYS1 dataset an alert is sent. But when I touch ZSECUR dataset there is no alert. I also tried OMVS.TEST dataset, just to use master-cataloged entry - no alert. ZSECUR datasets are cataloged in user catalog.
I cannot guess why the old entry or slightly renamed old entry (SYS1.ZSE.SENSITIV.RESOURC2) is being monitored, but any other are not.
Regards
------------------------------
Radosław Skorupka
------------------------------
Original Message:
Sent: 08/28/26 01:23 PM
From: Jeroen Tiggelman
Subject: zSecure Alert & Sensitive Resources puzzle
Hi Radoslaw,
Is the alert you are using based on SMF? If so, are SMF records being logged for this resource name or might it be a difference in the covering profiles' log settings?
Regards,
------------------------------
Jeroen Tiggelman
IBM - Software Development Manager IBM zSecure
Delft
------------------------------