IP Library Granted Patent US 8,738,768
Granted Patent B2
US 8,738,768 · App. 13/437,631 · Granted May 27, 2014

Multiple destinations for mainframe event monitoring

Inventors: Robert Fake (Clifton, VA); Deborah Gannaway (Tampa, FL)
Assignee: Meas, LLC
H04L41/06H04L41/0686H04L43/04H04L43/06H04L45/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,738,768
App. No.
13/437,631
Granted
May 27, 2014
Kind
B2
Abstract

Methods, systems, and devices are described for managing mainframe events. In the methods, systems, and devices of the present disclosure, at least one mainframe event is received at a mainframe event server module communicatively coupled with a mainframe. The received at least one mainframe event may be converted to an open format. A destination Security Information and Event Management (SIEM) application may be selected for the received at least one mainframe event based on a set of rules, and a format associated with the selected destination SIEM application may be identified. The at least one mainframe event may then be transmitted in the identified format from the mainframe event server module to the selected destination SIEM application.

Claims (53)

1. A method for managing mainframe events, comprising:

receiving at least one mainframe event at a mainframe event server module communicatively coupled with a mainframe, wherein the received mainframe events comprise mainframe events detected from at least one system management facility (SMF) log file associated with the mainframe and filtered according to at least one predetermined filtering criterion;

converting the received at least one mainframe event to an open format;

selecting a destination Security Information and Event Management (SIEM) application for the received at least one mainframe event based on a set of rules;

identifying a format associated with the selected destination SIEM application; and

transmitting the at least one mainframe event in the identified format from the mainframe event server module to the selected destination SIEM application.

2. The method of claim 1 , further comprising:

converting the received at least one mainframe event from the open format to the identified format associated with the selected destination SIEM application.

3. The method of claim 1 , further comprising:

determining a content of the at least one mainframe event;

wherein the selecting the destination SIEM application is based at least partly on the content of the at least one mainframe event.

4. The method of claim 1 , further comprising:

determining a type of the at least one mainframe event;

wherein the selecting the destination SIEM application is based at least partly on the type of the at least one mainframe event.

5. The method of claim 1 , wherein the transmitting the at least one mainframe event to the selected destination SIEM application comprises:

writing the at least one mainframe event to a text file associated with the selected destination SIEM application.

6. The method of claim 1 , wherein the transmitting the at least one mainframe event to the selected destination SIEM application comprises:

writing the at least one mainframe event to a syslog daemon associated with the selected destination SIEM application.

7. The method of claim 1 , wherein the transmitting the at least one mainframe event to the selected destination SIEM application comprises:

writing the at least one mainframe event to a relational data store associated with the selected destination SIEM application.

8. The method of claim 1 , wherein the mainframe events received at the mainframe event server module comprise mainframe events detected from a management console of the mainframe.

9. The method of claim 1 , wherein the open format comprises Common Event Format (CEF).

10. A mainframe event server system, comprising:

a reformatting module configured to receive at least one mainframe event associated with a mainframe and convert the received at least one mainframe event to an open format, wherein the received mainframe events comprise mainframe events detected from at least one system management facility (SMF) log file associated with the mainframe and filtered according to at least one predetermined filtering criterion;

a destination selection module configured to select a destination Security Information and Event Management (SIEM) application for the received at least one mainframe event based on a set of rules and identify a format associated with the selected destination SIEM application; and

a routing module configured to transmit the at least one mainframe event in the identified format from the mainframe event server module to the selected destination SIEM application.

11. The system of claim 10 , wherein the reformatting module is further configured to:

convert the received at least one mainframe event from the open format to the identified format associated with the selected destination SIEM application.

12. The system of claim 10 , wherein the destination selection module is further configured to:

determine a content of the at least one mainframe event;

wherein the selecting the destination SIEM application is based at least partly on the content of the at least one mainframe event.

13. The system of claim 10 , wherein the destination selection module is further configured to:

determine a type of the at least one mainframe event;

wherein the selecting the destination SIEM application is based at least partly on the type of the at least one mainframe event.

14. The system of claim 10 , wherein the routing module is further configured to:

write the at least one mainframe event to a text file associated with the selected destination SIEM application.

15. The system of claim 10 , wherein the routing module is further configured to:

write the at least one mainframe event to a syslog daemon associated with the selected destination SIEM application.

16. The system of claim 10 , wherein the routing module is further configured to:

write the at least one mainframe event to a relational data store associated with the selected destination SIEM application.

17. A mainframe event server system, the system comprising:

at least one processor;

at least one memory communicatively coupled with the at least one processor, the at least one memory comprising executable code that, when executed by the at least one processor, causes the at least one processor to:

receive at least one mainframe event associated with a mainframe, wherein the received mainframe events comprise mainframe events detected from at least one system management facility (SMF) log file associated with the mainframe and filtered according to at least one predetermined filtering criterion;

convert the received at least one mainframe event to an open format;

select a destination Security Information and Event Management (SIEM) application for the received at least one mainframe event based on a set of rules;

identify a format associated with the selected destination SIEM application; and

transmit the at least one mainframe event in the identified format from the mainframe event server module to the selected destination SIEM application.

18. The system of claim 17 , wherein the executable code further causes the at least one processor to:

convert the received at least one mainframe event from the open format to the identified format associated with the selected destination SIEM application.

19. The system of claim 17 , wherein the executable code further causes the at least one processor to:

determine a content of the at least one mainframe event;

wherein the selecting the destination SIEM application is based at least partly on the content of the at least one mainframe event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2012
From: FAKE, ROBERT; GANNAWAY, DEBORAH
To: MEAS, LLC
Reel/Frame 028923/0141 →
Continuity (2)
Provisional Application 61470333 · Mar 31, 2011
Related Publication 20120254313A1 · Oct 4, 2012