z/OSMF plug-in for IBM TDz

IBM Threat Detection for z/OS (IBM TDz) presents its results in the form of a graphical UI dashboard and activity timeline. The dashboard can help you to interpret each anomaly that is identified and can simplify diagnosis. The dashboard is added as a plug-in to your existing z/OSMF workspace.

The z/OSMF plug-in for IBM TDz contains two tasks, as follows:
Dashboard task
Main task. The Dashboard displays "donut-style" graphical displays for the sysplex and displays anomalies signatures of interest.
From the Dashboard task, you can perform the following activities:
  • View anomalies. By clicking Next Anomaly Signature in the upper left corner of the Dashboard, you can scroll through the list of anomalies.
  • View details for an anomaly signature event; click Details. Doing so launches the Details task in z/OSMF, which displays the data access anomalies for the selected time period.
  • Display a list of all anomalies at one time.
  • Customize the display by selecting a particular system or analytics boundary time period, or both. By default, the analytics boundary is set to one day or, if an alert was encountered, the time of the oldest alert within the last week.
Details task
This task is typically launched from the Dashboard when the user selects the Details view for a specific event.
In the Details task, you can view detailed activity over the 15-minute period that includes the anomaly, and view activity for 2 hour's worth of context. The Home button on the header displays the list of all hourly SMF data files, which were collected by the systems in the sysplex for a specified number of weeks. The user can select any SMF data file for analysis.

The Details task can also be launched on its own by clicking the Details icon directly from the z/OSMF desktop (rather than from within the IBM TDz plug-in). The task displays a list of all the SMF data files that are collected by the systems in the sysplex. The user can select any file to be analyzed and view the data access activity for that hour.