VitalSigns SIEM Agent for z/OS by Software Diversified Services integrates mainframe security events into your existing SIEM solution in real time. It allows you to quickly separate critical security incidents from regular events and send them in the appropriate format to your enterprise SIEM. VitalSigns SIEM Agent for z/OS collects mainframe security logs and messages from RACF, ACF2, Top Secret, DB2, CICS, FTP, and other sources. It filters thousands of event records based on your settings and sends the filtered records to your SIEM solution (e.g., Splunk, AlienVault, LogRhythm NextGen SIEM, IBM QRadar, ArcSight) in real-time. It helps comply with FISMA, GDPR, GLBA, HIPAA, PCI, SOX, and other standards. Administrators can define specific parameters to monitor in detail and automatically send data to any enterprise SIEM. With VitalSigns SIEM Agent for z/OS monitoring the mainframes, the security team has a central view of all events and security threats. Mainframe security no longer depends on batch jobs; events are tracked in real time from all areas of the business. This z/OS SIEM solution integrates with any distributed SIEM product and is certified for CEF and LEEF formats. It connects with standard z/OS security products and is certified for CEF and LEEF formats. Workload is zIIP eligible. It monitors z/OS and UNIX System Services (USS), gathers intelligence from z/OS SMF and the system operator interface, and uses both signature- and anomaly-based attack detection. It provides real-time alerts that can be managed, filtered, routed, and searched via SIEM software. APIs allow for defining and filtering TSO, CICS, and batch events. Easy installation does not require z/OS IPLs. It has a small footprint in each LPAR, with little CPU overhead. It provides end-to-end systems visibility for data security. It was recognized as one of the top 100 Trend-Setting Products by DBTA.