A fix is available
APAR status
Closed as program error.
Error description
RACF SMF TYPE=80 events with a missing CLASS do not result in a LEEF record being generated. For example SETROPTS LIST events are missing.
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: Users of zSecure Audit exploiting the * * software to prepare data for QRadar SIEM. * **************************************************************** * PROBLEM DESCRIPTION: The zSecure Audit QRadar SIEM interface * * might generate LEEF files that does not * * contain records of RACF events with a * * missing class name. * **************************************************************** * RECOMMENDATION: Apply the PTF provided. * **************************************************************** When a SMF source being processed by zSecure Audit contains RACF event records without a RACF class, the generated LEEF file does not contain such records at all.
Problem conclusion
The zSecure Audit QRadar SIEM interface has been modified so that it properly writes LEEF records for SMF events without a RACF class name.
Temporary fix
Comments
APAR Information
APAR number
OA62236
Reported component name
ZSEC BASE,ADMIN
Reported component ID
5655T0100
Reported release
240
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-10-07
Closed date
2021-10-19
Last modified date
2021-11-01
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UJ06844 UJ06845
Modules/Macros
CKQLEEF CKQLEEFL
Fix information
Fixed component name
ZSEC BASE,ADMIN
Fixed component ID
5655T0100
Applicable component levels
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"240"}]
Document Information
Modified date:
02 November 2021