What SMF records
SMF is z/OS's flight recorder. As work runs, z/OS and the products on it write numbered records describing what happened: who ran what, how much processor and I/O it used, who touched which dataset, and how the system performed.
The system's flight recorder
SMF (System Management Facilities) is a z/OS component that collects records from the operating system, from subsystems such as Db2, CICS and MQ, and from many vendor products. Each record has a record type number from 0 to 255, and many types have subtypes. Nothing is shown on a screen while it happens: SMF is written to datasets or log streams and read later by reports and tools.
SMF exists because a shared machine needs evidence. Finance wants to know which department used the processor, auditors want to know who opened a sensitive dataset, and capacity planners want months of history. SMF gives all of them one consistent source, which is why it is often called the single most important dataset on the platform after the system itself.
Record types you will meet
There are hundreds of record types, but a working set of a dozen covers most daily questions. Types 0 to 127 are reserved for IBM; 128 to 255 are available to the installation and vendor products, so a vendor tool's record number varies by site.
| Type | Written by | What it tells you |
|---|---|---|
| 14 / 15 | z/OS data management | A non-VSAM dataset was closed after input (14) or output (15): which job, which dataset, how much I/O |
| 30 | z/OS | Common address space work: job and step start, end and interval data, CPU time, EXCP counts, accounting fields |
| 70 | RMF Monitor I | Processor activity, including LPAR and partition data |
| 71 - 78 | RMF Monitor I | Paging, workload activity (72), channels (73), devices and coupling facility (74), page datasets (75), enqueue contention (77), I/O queuing (78) |
| 79 | RMF Monitor II | Snapshot data from Monitor II sessions, when recording is requested |
| 80 | RACF | Security events: violations and events selected for auditing |
| 101 | Db2 | Accounting: per-thread elapsed time, CPU, SQL counts and waits |
| 110 | CICS | Transaction monitoring and statistics data |
Other types you may hear about include 100 (Db2 statistics), 115 and 116 (MQ statistics and accounting) and 119 (TCP/IP). Whether a type is written at all depends on the product's own settings: Db2 only writes 101 if accounting traces are started, and CICS only writes 110 transaction records if monitoring is switched on.
The type 30 record: the workhorse
Type 30 is the record most people use first. Its subtypes describe the life of a job: subtype 1 when work starts, 2 and 3 for interval records, 4 at the end of each step, 5 at the end of the job, and 6 for system address space intervals. Each record carries the job name, job ID, user, the accounting information from the JOB statement, CPU time split into TCB and SRB time, time on zIIP processors, and I/O counts.
JOBNAME STEPNAME PGM RC TCB-CPU SRB-CPU ZIIP EXCP PAYD010 STEP020 PAYCALC 0000 00:01:42 00:00:03 0.00 184,220 PAYD010 STEP030 SORT 0000 00:00:21 00:00:01 0.00 52,907 PAYD010 STEP040 IKJEFT01 0004 00:00:09 00:00:00 00:00:11 3,114
How products use SMF
- Performance and capacity: RMF writes types 70 to 79, and every performance tool on the platform reads them.
- Accounting and chargeback: type 30 plus subsystem accounting (101, 110, 116) split usage by department or application.
- Security and audit: type 80 records what RACF checked and denied; other security products also write SMF.
- Problem diagnosis: type 14/15 and 30 records answer 'which job wrote this dataset last night, and when?'
Which SMF record type does RACF write for security events such as access violations?
Show a hint
It is a two-digit number in the 80s.
Show the solution
Type 80. RACF writes SMF type 80 records for violations and for events selected for auditing.
Common mistakes
Record types can be switched off in SMFPRMxx, and subsystems such as Db2 and CICS only write some records when traces or monitoring are active. Check before promising a report.
Types 128 to 255 are assigned by each site to vendor and local products. A record 'type 200' means different things at different companies.
A job's total hides which step burned the time. Type 30 subtype 4 gives per-step figures; use them before blaming a program.
What you will see at work
- Production support uses type 30 and 14/15 data to answer 'what ran, when, and what did it write' after an incident.
- Auditors regularly ask for type 80 extracts showing who accessed protected datasets during a period.
- Performance and capacity teams keep RMF types 70 to 79 for months or years to show trends.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.