Deployment Architecture

TSM with Splunk

Hema_Nithya
Explorer

Hi

We are trying integrate TSM servers with splunk and create a dashboard . Please assist what are logs we need to feed the splunk from the TSM server , fyi TSM servers are already integrated in the Splunk .

Tags (3)
1 Solution

dwaddle
SplunkTrust
SplunkTrust

Big question. TSM has a lot of data available, and what do you want to do with it exactly? "What problem are you trying to solve, exactly?" is always a good question.

One good simple starting point is the dsmaccnt.log file. It's a basic CSV of performance and accounting data around every TSM server connection. Lots of good data there, and it's simple to ingest and parse.

Beyond that, there's several good data points inside the TSM database itself, such as the activity log, the summary data, the nodes table, and several other things. In "modern" TSM (V6.1 and above) all of this is stored in DB2, so you might be able to get at it using the DB Connect app pretty easily.

If you aren't deeply familiar with both TSM and Splunk this might be the right kind of job to turn over to Professional Services to help you figure out how to ingest this data.

View solution in original post

0 Karma

zerotosixty2
Engager

It is possible to run a scheduled script to collect information from TSM using dsmadmc and SQL and store it in a comma separated file. use a universal forwarder to put this data into splunk and then extract those metrics into a dashboard.

some examples:

DB space
Tape drives in use
Scratch Tapes remaining
Drives offline

0 Karma

Hema_Nithya
Explorer

Tivoli Storage Manager AIX machines are integrated and OS level logs are ingested in the splunk already , now we are planning get the Application (TSM) to the splunk , for example to get a dashboard report weekly occupancy report .. backup success rate , nodes data ..

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Big question. TSM has a lot of data available, and what do you want to do with it exactly? "What problem are you trying to solve, exactly?" is always a good question.

One good simple starting point is the dsmaccnt.log file. It's a basic CSV of performance and accounting data around every TSM server connection. Lots of good data there, and it's simple to ingest and parse.

Beyond that, there's several good data points inside the TSM database itself, such as the activity log, the summary data, the nodes table, and several other things. In "modern" TSM (V6.1 and above) all of this is stored in DB2, so you might be able to get at it using the DB Connect app pretty easily.

If you aren't deeply familiar with both TSM and Splunk this might be the right kind of job to turn over to Professional Services to help you figure out how to ingest this data.

0 Karma

woodcock
Esteemed Legend

What is TSM?

0 Karma

woodcock
Esteemed Legend

You say you are "trying to integrate TSM servers with Splunk" and then "TSM servers are already integrated in the Splunk". Which is it? What EXACTLY are you trying to do and what EXACTLY is already done/working?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...