IBM Support

OA52369: LEEF DATA RECORDS CONTAIN BINARY DATA IN THE LOG STRING FROM DB2.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • ERROR DESCRIPTION:Ø
    DB2 places a binary STCK value in the log string when calling
    RACF.  The production of LEEF data carries the binary values to
    the output, resulting in parsing errors in Qradar.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting the        *
    *                 software to prepare data for QRadar SIEM.    *
    ****************************************************************
    * PROBLEM DESCRIPTION: The zSecure Audit QRadar SIEM interface *
    *                      might generate LEEF files that contain  *
    *                      unprintable characters in the 'logstr=' *
    *                      operand from a DB2 subsystem.           *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    When the zSecure Audit QRadar SIEM interface processes SMF data
    that contain records produced by a DB2 subsystem with log
    strings, the generated LEEF file contains characters that cause
    parsing errors issued by QRadar SIEM.
    

Problem conclusion

  • The zSecure Audit QRadar SIEM interface has been modified so
    that the 'logstr=' operand for events issued by a DB2 subsystem
    contains a human readable timestamp value instead of binary
    data. Please note the documentation changes as provided by the
    APAR tracking comment data.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA52369

  • Reported component name

    AUDIT-R,A,T ACF

  • Reported component ID

    5655T0200

  • Reported release

    220

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-03-21

  • Closed date

    2017-04-07

  • Last modified date

    2017-05-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UA91549 UA91550

Modules/Macros

  •    CKAFMTA  CKQLEEF  CKQLEEFL CKRINMO  CKROUNIT
    C2ELEEF  GKRFMTA  GKRINMO  GKROUNIT
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R220 PSY UA91549

       UP17/04/08 P F704

  • R221 PSY UA91550

       UP17/04/08 P F704

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"}, "Product":{"code":"SSCE68R","label":"zSecure Admin"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"220","Edition":""}]

Document Information

Modified date:
01 May 2017