All excellent ideas. Thank you.
------------------------------
Robert Berendt IBMChampion
Business Systems Analyst, Lead
Dekko
Fort Wayne
------------------------------
Original Message:
Sent: Wed June 11, 2025 06:47 AM
From: Marius le Roux
Subject: What kind of QRadar messages might an IBM i admin want to see?
Hi Robert,
A few that I might find useful:
- Subsystem Information.(started or ended)
- CPU Thresholds perhaps reached in certain time intervals.
- System User password expired or disabled. (or attempted usage of those privileged profiles as attack indicator).
- Critical Job failures (day end jobs).
- Job tables details (if your system needs an IPL soon).
- When last the system was IPLed and perhaps for what reason (sort of like when you shutdown a windows server if it was planned , why did the shutdown occured?)
Preventative Security PTFs that need to be installed on the system - send the notification on alert - When a privileged user like QSECOFR signs on and off. (perhaps also REASON why someone used that as interactive login the first place).
- Critical messages (those that exist in QSYSMSG for example).
- Job Monitoring (some Long running SQL / Batch Jobs that might be looping and causing resources?)
- Regular checks on how many interactive users are signed in (this is helpful for determining usage thresholds on peak periods for example).
- Webservice status - if any failure and when was the last time started. (same with a threshold set in HTTP REQUESTS , if that threshold is reached, send the message to SIEM, could be someone DDOSing service in peak /offpeak time).
------------------------------
Marius le Roux theIBMiGuy
Owner , IBM i Consultant & Technology Strategist
MLR Consulting
Original Message:
Sent: Tue June 10, 2025 07:52 AM
From: Robert Berendt
Subject: What kind of QRadar messages might an IBM i admin want to see?
Let's say you are sending messages to a SIEM like IBM's QRadar from IBM i. Now you're about to undergo training in getting reports from QRadar. What are the general messages one might see from QRadar? These messages get to QRadar from IBM's Syslog Reporting Manager (SRM), etc.
- Repeated invalid logins?
- Diskspace messages?
- Expiring licenses?
- Hardware errors?
------------------------------
Robert Berendt IBMChampion
Business Systems Analyst, Lead
Dekko
Fort Wayne
------------------------------