VSA - Sending z/OS Events to SIEM
Although mainframes produce a lot of information about what is happening (event log, audit log, syslog, etc.), it is necessary to quickly and easily separate critical security incidents from common business events - and send them in the correct format to your corporate SIEM.
The VitalSigns SIEM Agent for z/OS (VSA) forwards security messages and logs from the mainframe environment (such as RACF, ACF2, Top Secret, DB2, CICS, and FTP, etc.), in the appropriate format, to Security Event Management Systems (SIEM) , such as Splunk®, LogRhythm NextGen SIEM, IBM® QRadar®, AlienVault, ArcSight, and others.
VSA places mainframes at the center of the enterprise security infrastructure in real time, and without complications.
This SIEM solution for z/OS is flexible enough to integrate with any SIEM product and is certified for CEF and LEEF formats.
VSA is a product ready for use with IBM's security solution.
Furthermore, VSA integrates well and provides mainframe data to SIEM solutions:
Splunk, LogRhythm NextGen SIEM, AlienVault, ArcSight, McAfee® Enterprise Security Manager and others.
COMPLIANCE
O VSA é uma poderosa ferramenta para ajudar sua empresa no atendimento aos padrões FISMA, GDPR, GLBA, HIPAA, PCI, SOX, entre outros.
Os administradores podem definir parâmetros específicos para monitorar com mais detalhes e maior profundidade, o envio automático de dados para qualquer SIEM corporativo.
SECURITY
With VSA monitoring the mainframes, your security team will have a centralized view of the entire enterprise and all events that need to be captured, as well as all security threats that need to be recognized.
TRANSPARÊNCY
Mainframe security no longer needs to rely on jobs running long after an incident. Events are tracked and discovered in real time, from all corners of the business.
Features
-
Provides mainframe data to most SIEM products
-
Certified for CEF and LEEF formats
-
Connects to standard z/OS security products
-
Reduces CPU cycles by offering zIIP support (starting with version 4.3 – view the benchmark)
-
Monitors z/OS and UNIX System Services (USS)
-
Gathers intelligence from z/OS SMF and the system operator interface
-
Uses signature- and anomaly-based attack detection
-
Real-time alerts that can be managed, filtered, routed, and searched via SIEM software
-
APIs allow for the definition and filtering of TSO, CICS, and batch events
-
Easy installation; does not require z/OS IPLs
-
Low resource footprint on each LPAR and low CPU overhead
