1607_diagnostic – Capture SMF flood diagnostics for zSecure alert C2P1607I
Synopsis
Capture system diagnostics when zSecure alert C2P1607I (SMF Record Flood) is detected.
This playbook runs as the first job in the EDA - SMF 1607 Response Workflow, which the
1607_SMF_Flood_Alert - Monitor zSecure alerts from Kafka for SMF Record Flood alert rulebook triggers. The playbook issues the D SMF operator
command to capture the current SMF recording status on the target z/OS system, extracts the
SMF record type and flood detection time from the correlated IFA780A WTO message, and
publishes the derived values for downstream notification jobs in the same workflow.
Variables
From the EDA event context
These variables are available automatically to all jobs in an EDA-launched workflow through
ansible_eda.events. This playbook must run inside the EDA - SMF 1607 Response Workflow;
the workflow must be triggered by the EDA rulebook for these references to be populated.
- ansible_eda.events.c2p1607i.body.alert_code
The zSecure alert code, always
C2P1607Ifor this workflow.type: str- ansible_eda.events.c2p1607i.body.hostname
The z/OS system name where the SMF record flood was detected.
type: str- ansible_eda.events.ifa780a.body.alert_message
The IFA780A WTO message text. Read by the playbook
vars:block asflood_wto_messageand used to extract both the SMF record type and the flood detection time by using a regular expression.type: str
From the AAP job template
Ensure that these variables are defined on the AAP job template that launches the playbook:
- target_hosts
The inventory host or group where the
D SMFoperator command is issued. Defaults tolocalhostif not specified on the job template.type: str- system_environment
Environment variables required for z/OS shell access, such as shared address space settings.
type: dict
How the playbook works
The playbook runs in five steps.
Step 1: Capture current SMF status
The playbook issues the D SMF operator command on the target z/OS system by using the
ibm.ibm_zos_core.zos_operator module. Both ignore_errors: true and
ignore_unreachable: true are set so that a command failure does not abort the workflow.
If the command succeeds, the playbook formats the raw console response into the d_smf_output
variable, prefixed with a ==== D SMF ==== header for clarity in the notification email.
If the command fails or the host is unreachable, a separate fallback task sets d_smf_output
to a static message (D SMF command could not be executed.) so that subsequent steps and
the notification email always have a defined value.
Step 2: Extract the SMF record type
The playbook parses the flood_wto_message variable — resolved from
ansible_eda.events.ifa780a.body.alert_message in the vars: block — by using
regex_findall to extract the numeric SMF record type that
triggered the flood filter. If the pattern does not match — for example, if the message text is
absent or malformed — the variable is set to UNKNOWN so the workflow can continue without
interruption.
Step 3: Extract the flood detection time
The playbook parses the same flood_wto_message variable by using regex_findall to extract
the time at which the flood was detected. If no time value is found in the message, the variable
is set to UNKNOWN.
Step 4: Display diagnostic summary
The playbook logs a formatted summary to the AAP job output, including the alert code, resolved
SMF record type, flood detection time, hostname, and D SMF command status (Success or
Failed). This output is visible in the AAP job log for review.
Step 5: Publish derived results for downstream jobs
The playbook publishes smf_record_type, smf_flood_time, and d_smf_output by using
ansible.builtin.set_stats so they are available to subsequent jobs in the
EDA - SMF 1607 Response Workflow, specifically the notification job that renders and sends
the alert email.
Output
The playbook produces three workflow-level outputs by using set_stats:
smf_record_type: The numeric SMF record type extracted from the IFA780A message, or
UNKNOWNif extraction failed.smf_flood_time: The flood detection time extracted from the IFA780A message (format
HH.MM.SS), orUNKNOWNif extraction failed.d_smf_output: The formatted output of the
D SMFoperator command, including the==== D SMF ====header, or a fallback message if the command could not be executed.
The send_1607_alert_email – Send HTML email notification for SMF Record Flood alert playbook uses all three values to populate the HTML notification email.
Prerequisites
The AAP job template must include a Machine credential for z/OS SSH access.
The z/OS user running the playbook must be authorized to issue the
D SMFoperator command.The
ibm.ibm_zos_corecollection must be installed in the execution environment.Ensure that this playbook runs as a job inside the EDA - SMF 1607 Response Workflow, as it depends on
ansible_eda.eventsthat is populated by the EDA rulebook.
Notes
The playbook sets
gather_facts: falsebecause no Ansible facts are required for the operator command or regex extraction.The
D SMFoperator task usesignore_errors: trueandignore_unreachable: trueso that a command failure or an unreachable host does not abort the workflow. If either condition occurs, the fallback task setsd_smf_outputtoD SMF command could not be executed.so that the notification email always has a defined value for the diagnostics section.The
D SMFcommand output is joined into a single multi-line string. On systems where the operator command produces a large response, the output is truncated to what theibm.ibm_zos_core.zos_operatormodule returns.If
flood_wto_messageis empty or does not contain the expected pattern, bothsmf_record_typeandsmf_flood_timeare set toUNKNOWNand the email renders cleanly with that placeholder value.Step 4 logs alert details to the AAP job log. Restrict access to job logs as required by your security policy.
set_statspublishes data at the AAP workflow level, making all three variables available to all subsequent jobs in the workflow.
See also
The 1607_SMF_Flood_Alert - Monitor zSecure alerts from Kafka for SMF Record Flood alert rulebook that triggers this playbook as part of the response workflow.
The send_1607_alert_email – Send HTML email notification for SMF Record Flood alert playbook that consumes
smf_record_type,smf_flood_time, andd_smf_outputto send the notification.To issue operator commands on z/OS, see the ibm.ibm_zos_core.zos_operator module.