What do we need to do to turn on SMF recording for TSS

Document ID : KB000113791
Last Modified Date : 24/09/2018
Show Technical Document Details
Introduction:
Top Secret SMF records for zSecure Qradar
Question:
Questions: 1. We need TSS SMF records for zSecure/Qradar.Need to know what is need to set to collect SMF records for TSS
Environment:
z/os
Answer:
Questions: 1. We need TSS SMF records for zSecure/Qradar. Any of your clients use zSecure?
Answer: Couldnt find any related zSecure related tickets for CA Top Secret.
2. What SMF records do they collect?
Answer: CA Top Secret write SMF80 and SMF231 records to the SMF dataset.
SMF80 is the same information that is written to the Audit Tracking File.
SMF231 is the USS related audited events.
3. Will there be a lot of overhead doing SMF recording and using TSS Audit tracking file at the same time?
Answer: What ever is written to the AUDIT tracking file will also be written to the SMF80 record with LOG(SMF) set.
. So what are the changes to parms are needed?
LOG(SMF) needs to be set for the Audit entries to be written to the audit tracking file as SMF80 recorrds.
SMF231 records are always written to the SMF dataset which contain the USS audit informatioin.