Collecting, dumping and archiving SMF
The SMFPRMxx parmlib member controls what SMF records and where it writes them. Records go to SYS1.MANx datasets or, more commonly today, to log streams, and a daily job dumps them to archive datasets that are kept for years.
SMFPRMxx: the control member
SMF is configured by an SMFPRMxx member in parmlib, chosen at IPL and changeable while the system runs. It says whether recording is on, which record types and subtypes to keep, whether to write to datasets or log streams, how often interval records are produced, and which exits run. Systems programmers own it; changes go through change control because a wrong value can silently stop audit or billing data.
ACTIVERECORDING(LOGSTREAM)DEFAULTLSNAME(IFASMF.DEFAULT)LSNAME(IFASMF.PERF,TYPE(70:79))SYS(TYPE(0:255),EXITS(...))INTVAL(15)SYNCVAL(00)Useful operator commands: D SMF shows the current recording status, SET SMF=xx activates a different SMFPRMxx member, and SETSMF changes individual parameters. Your site may restrict who can issue these.
Datasets or log streams
With datasets, the I SMF (SWITCH SMF) command forces a switch to the next MANx dataset, which is a common step before dumping. With log streams there is no switching: the dump program reads the log stream by date and time range.
Dumping and archiving
Two IBM programs move SMF data into ordinary sequential datasets: IFASMFDP for SYS1.MANx datasets and IFASMFDL for log streams. Both can select record types and write different types to different output files, so a site can keep RMF data in one archive and security data in another.
//SMFDUMP EXEC PGM=IFASMFDL //SYSPRINT DD SYSOUT=* //OUTALL DD DSN=SMF.DAILY.ALL(+1),DISP=(NEW,CATLG),... //OUTSEC DD DSN=SMF.DAILY.SEC(+1),DISP=(NEW,CATLG),... //SYSIN DD * LSNAME(IFASMF.DEFAULT,OPTIONS(DUMP)) OUTDD(OUTALL,TYPE(0:255)) OUTDD(OUTSEC,TYPE(80)) RELATIVEDATE(BYDAY,1,1)
Outputs are usually GDG generations, later consolidated into weekly and monthly archives on tape or virtual tape. Retention is a business decision: audit and regulation may require years of security records, while detailed interval data might be summarised after a few months. Many sites also feed SMF to analytics tools such as IBM Z Performance and Capacity Analytics, MXG (SAS-based), IntelliMagic Vision, or a SIEM through forwarders such as Precisely Ironstream.
Modern relevance
- Recent z/OS releases support real-time access to SMF data through in-memory resources, used by tools that stream records off the platform.
- SMF records can be digitally signed on current z/OS levels so tampering can be detected, which matters for audit.
- Volumes have grown with Db2, CICS and TCP/IP data; compression and selective recording keep archives manageable.
Common mistakes
It is not 'just housekeeping'. With dataset recording, a failed dump can lead to lost records. Treat it as production-critical and restart it promptly.
Removing types 70, 80 or 89 can break audit, chargeback and software licence reporting. Agree changes with every data owner first.
Check dump job outputs and record counts. Gaps are found by auditors months later, when they cannot be fixed.
What you will see at work
- Operations run the daily SMF dump and archive jobs in the batch schedule, often early each morning.
- Systems programmers maintain SMFPRMxx and the log stream definitions under change control.
- Security and capacity teams each pull their own record types from the shared archive.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.