Document toolboxDocument toolbox

box.ibm

Introduction

The tags beginning with box.ibm identify events generated by IBM z/OS.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as box.ibm. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

IBM z/OS

box.ibm.z_os.fim

box.ibm.z_os.fim

box.ibm.z_os.leef

box.ibm.z_os.leef

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

box.ibm.z_os.fim

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

event

str

 

type

str

 

scan_id

str

 

prev_scan_id

str

 

res_set

str

 

class

str

 

mon_type

str

 

res_set_grp

str

 

agent

str

 

agent_grp

str

 

os_type

str

 

opt

str

 

entries

str

 

added

str

 

removed

str

 

modified

str

 

malicious

str

 

kbytes

str

 

cpu

str

 

elapse

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓

box.ibm.z_os.leef

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

leefVer

str

 

vendor

str

 

product

str

 

version

str

 

eventID

str

 

devtimeformat

str

 

devtime

str

 

usrname

str

 

job

str

 

class

str

 

prof

str

 

res

str

 

terminal

str

 

poe

str

 

desc

str

 

reason

str

 

sum

str

 

name

str

 

usrpriv

str

 

intent

str

 

vol

str

 

dsn

str

 

own

str

 

box

str

 

action

str

 

sens

str

 

jobid

str

 

program

str

 

stepname

str

 

compcode

str

 

path

str

 

bypass_req

str

 

storclas

str

 

mgmtclas

str

 

auth

str

 

member

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓