Mainframe Path Start learning free
Applied10 min readLesson 2 of 3

Getting mainframe data into enterprise platforms

Most organisations run one observability or log platform for everything, such as Splunk, Elastic or Grafana. Mainframe data can feed it through streaming collectors, so one dashboard can show the whole service. Doing it well means choosing data carefully, handling formats, and respecting cost and sensitivity.

Why bring it together

A customer's payment might pass through a mobile app, an API gateway, cloud services, MQ, CICS and DB2. If each team looks only at its own console, an incident turns into a meeting where everyone shows a green screen. Putting mainframe data next to distributed data lets one team see where the time went.

How data moves

A typical streaming pipeline
SourcesSMF, SYSLOG, OPERLOG, logs
Collector on z/OSreads and filters
Transformdecode, convert, enrich
TransportTCP, Kafka, HTTP
PlatformSplunk, Elastic, Grafana stack

A collector runs on z/OS, often as a started task. It reads SMF records, log streams or files, filters them, and sends them off-platform. Examples include IBM Z Common Data Provider, Syncsort/Precisely Ironstream, and data forwarding built into product monitors. Some sites use vendor connectors to Apache Kafka as a hub so many consumers can read the same stream.

What has to be transformed

Choosing a platform role

PlatformTypical role
SplunkLog and event search, security analytics, dashboards; widely used for SMF and SYSLOG
Elastic (Elasticsearch, Kibana)Search and dashboards for logs and metrics, often self-managed
Prometheus and GrafanaTime-series metrics and dashboards; Grafana can also chart data from other stores
Vendor APM and observability suitesTraces, service maps and AI-assisted alerting across tiers

None of these is the right answer everywhere. Pick based on what the rest of the organisation already uses, so mainframe data lands where the incident responders already look.

OpenTelemetry at concept level

OpenTelemetry (OTel) is an open-source, vendor-neutral standard from the Cloud Native Computing Foundation for producing and shipping metrics, logs and traces. Its value is that instrumented software can send data to any compatible back end. IBM and other mainframe vendors have been adding OpenTelemetry support to some products; what is supported depends on the product and version, so check before you design around it.

Cost, security and ownership

Common mistakes

Sending everything

Full-volume SMF can overwhelm ingest budgets and the platform. Start from the questions you need answered and select record types and fields.

Ignoring time zones

Mixed local and UTC timestamps make correlated timelines wrong. Normalise to UTC and record the source system.

Forgetting the data is sensitive

Off-platform copies need the same protection as the source. Mask fields and restrict who can search them.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
← Monitoring, observability and z/OS telemetryGolden signals, alerts and end-to-end tracing →