IBM Security Z Security

 View Only
  • 1.  zSecure alert for DB2 Audit

    IBM Champion
    Posted Sun February 20, 2022 07:00 AM

    Hello 

    Does anyone has created a zSecure alert for DB2 audit.

    Did not find documentation on how to write those kind of alerts

    Very appreciated if someone could help.

    Regards Chiara



    ------------------------------
    Chiara Baldan
    ------------------------------


  • 2.  RE: zSecure alert for DB2 Audit

    Posted Mon February 21, 2022 02:00 AM
    Hi Chiara,

    What kind of Db2 auditing are you trying to achieve?

    Regards,

    ------------------------------
    Jeroen Tiggelman
    Software Development and Level 3 Support Manager IBM Security zSecure Suite
    IBM
    Delft
    ------------------------------



  • 3.  RE: zSecure alert for DB2 Audit

    IBM Champion
    Posted Mon February 21, 2022 02:15 AM
    Hello Jeroen,
    I am trying to help out a customer, he is interested in monitoring violations.
    Something like receiving an alert after a number of access attempts to a resource in db2.
    He is also open to understand what kind of alerts could be build on Db2.
    Regards
    Chiara


    ------------------------------
    Chiara Baldan
    ------------------------------



  • 4.  RE: zSecure alert for DB2 Audit

    Posted Mon February 21, 2022 04:17 AM
    Hi Chiara,

    DB2 can write IFCID 140s to audit on violations if you have started an Audit trace for it. 

    https://www.ibm.com/docs/en/db2-for-zos/12?topic=db2-audit-trace

    these are writen as SMF 102's. Alert can collect these but mind that we cannot collect on specific IFCID's. So you could get a lot of them (and mostly irrelevant) which are all fed to the CARLa engine and that might be costly in term of CPU usage.

    by using an audit trace for other classes you might be able to report on other things too. Using option EV.4 can show you what kind of info we can display.

    cheers

    rene

    ------------------------------
    RENE van TIL
    ------------------------------



  • 5.  RE: zSecure alert for DB2 Audit

    IBM Champion
    Posted Mon February 21, 2022 04:36 AM
    Hello Rene,
    thanks for the info.
    is there a way to set up a custom alert to filter on a specific IFCIDS's, once they are all fed to the CARLa engine?


    ------------------------------
    Chiara Baldan
    ------------------------------



  • 6.  RE: zSecure alert for DB2 Audit

    Posted Mon February 21, 2022 04:45 AM
    Hi chiara,

    select TYPE=102(140) should do it. EV.4 with event selection 3 (Only select violations) doess that too

    cheers

    rene

    ------------------------------
    RENE van TIL
    ------------------------------