Each dataset in the data model requires IBM i sourced data to be available in your Splunk environment. If a given type of data is not available, then the corresponding model dataset and/or fields cannot be populated.
There is no requirement to populate all datasets. For example, the Disks dataset may not be populated because QAPMDISK data is not collected from an LPAR due to its volume.
This table shows the IBM i data sources required in your Splunk system to populate the data model datasets.
Dataset |
|
|---|---|
Authority Failures |
QAUDJRN: EntryType: AF |
Command Usage |
QAUDJRN: EntryType: CD |
Critical Messages |
Message Queues including QHST |
Disks |
QAPMDISK |
Invalid Logons |
QAUDJRN: EntryType: PW |
ITOA LPAR Names |
QAPMSYSTEM, QAPMISUM, QAPMPOOLB, QAPMDISK, QAPMTCP |
Job Type Summary |
QAPMJSUM |
Jobs |
QAPMJOBMI, QAPMJOBOS |
LPAR Summary |
QAPMISUM, QAPMSYSTEM |
Memory Pools |
QAPMPOOLB |
Network Summary |
QAPMTCP |
Object Activity |
QAUDJRN: EntryType: CO, DO, OM, OR |
Profile Changes |
QAUDJRN: EntryType: CP |
System Values |
QAUDJRN: EntryType: SV |
For more detail on the Audit Journal (QAUDJRN) fields that Ironstream provides, refer to the Ironstream for Splunk for IBM i Administration Guide (Ironstream_Integration_Components_Admin_Guide_V73.pdf).