Collecting System Audit Journal (QAUDJRN) Data - ironstream_for_elastic - ironstream_for_splunk - ironstream_for_kafka - Ironstream_Hub - 1.3

Ironstream Hub Administration

Product type
Product family
Ironstream > Ironstream for Splunk®
Ironstream > Ironstream for Elastic®
Ironstream > Ironstream Hub
Ironstream > Ironstream for Kafka®
Product name
Ironstream Hub
Ironstream Hub Administration
First publish date

Collecting system audit journal data is done by adding the system audit journal (QAUDJRN) to a Journal Monitor Group using the Configuration Tool. System audit journal records are sent to Hub as 'raw' unformatted records. Hub Server will process the raw records and create JSON formatted records for ingestion by the target.

Do these steps to configure audit journal configuration:

  1. Launch the Configuration Tool.
  2. Select the Journal Monitors tab.
  3. Choose an existing journal monitor group if one has already been created, or create a new group using the Create button. Choose a name for the monitor group.
  4. Enter a Frequency interval (in seconds) to select how often the journal is polled for new entries. Use increments of 30 seconds.
  5. On the Journal Monitor Group page, click Add Monitor to add the system audit journal.
  6. In the configuration screen, enter QAUDJRN in the Journal Name field and QSYS in the Journal Library field.
  7. Ensure Raw is checked.
  8. Ensure the Field Description Config selection is left blank and is ignored when Raw is selected.
    Figure 1. Add the System Audit Journal
  9. To send all supported entry types:
    1. Enter T for the Entry Code.
    2. Do not add individual entry types.
  10. To send only selected journal entry types:
    1. Leave the Entry Code empty.
    2. Click the Add Type button to add an entry type.
    3. To add additional entry types, continue to click the Add Type button.
    Figure 2. Add Specific Journal Entry Types
  11. Fill in the Assigned systems field to assign the completed Journal Monitor Group to one or more IBM i LPARs.
  12. Click the Save button.
  13. Click the Distribute button to send the monitor group to the Ironstream Agent for IBM i for the Assigned systems.
  14. On the Systems tab, restart each System that is in the Assigned systems list of the newly created Journal Monitor Group.
    Note: After creating or changing a journal monitor, you MUST restart each Source affected by the changes to ensure that Hub is using the new configuration details when processing journal entries.