Using Association Monitor
Navigating the Associations tab
To access the top-level Associations screen, select Correlations > Associations. All association features and functions are available on the Associations tab, as displayed in the following image:

(SPE2404) The Correlation > Association tab contains a list of Association Definitions available on the system. Each definition shows:
- Association Definition name
- Description hidden in a (question) tooltip
- Disabled Association Definitions have a line indicating the disabled state.
- Links to All Data, Field 1, and Field 2. The two field links will display the field labels for the Association Definition.
- Data Columns–These columns will have data only if the Association Definition has data
- Last Message–Date and time of the last message associated
- Unique Associations–This is the count of unique Association Values that have been encountered. Two values are provided, one for Today and one for History (the total count since initial creation).
- Associated Messages–This is the count of messages that have been associated with this definition across all Association Values. Two values are provided, one for Today and one for History (the total count since initial creation).
The following default Association Definitions are provided and are configured to work with the BMC AMI Datastream programs:
- CICS - Userid and CICS File Name Access
- CICS - Userid and CICS Transactions
- Db2 - Userid and Db2 DBID
- Db2 - Userid and Db2 Grantor
- ICSF - Userids and Jobnames
- IMS - Userid and DBName
- IMS - Userid and IMS ID
- Sensitive Dataset Accesses
- Sensitive Dataset Member Accesses
- SessMon - Userid and Appl ID
- Userid and DSN
- Userid and Honeypot DSN
- Userid and LPAR Terminal
- Userid and MQs
- Userid and PII DSN
- Userid and Time Logged In
Before SPE2410:
- DB2_User And DB2_Grantor
- Db2_Userid And Db2_DBID
- IMSDBName And Userid
- IMSID And Userid
- User And DSN
- User And LPAR Terminal
- User And Terminal
- Userid And Hour Logged In
- Userid And Time_Logged_In
- Users And CICS File Name Acces
- Users And CICS Transactions
- Users And MQs
- (SPE2407) SessMon: Userid And Appl ID
To add new associations as an admin, select AddNew.
To edit or delete an existing Association Definition as an admin, select Edit #NN to the left of each association.
Using the Association Monitor advanced features
The previous section provided an overview of operation that is typically sufficient to operate Association Monitor, including the ability to configure associations using both simple and advanced techniques. This section elaborates on this information, providing additional information on several advanced features (available using the Advanced option at the top of the screen).
These more advanced features allow the system to perform additional functions, such as automatic statistical analysis of associations for outliers and anomaly detection. These functions can also be useful for exporting data to a relational database for more analysis and reporting.
This section provides a description of the advanced features of the system and the various configurable parameters. The information in this section should be of interest to advanced system users, as well as administrators looking for ways to further leverage the association data collected by BMC Defender.
To modify the advanced parameters
- Navigate to Correlation > Associations > Config > Edit.
You must be an admin type user to access the advanced parameters. The following figure displays the advanced configuration parameters on the Associations tab.
Modify the following parameters:
Parameter
Description
Max Associations
(Deprecated from SPE2410 onwards) maximum number of associations available to the system. This is a read-only field and you cannot modify it.
Drop Unreferenced Associations Older Than
(Deprecated from SPE2410 onwards) duration of an association that has not been updated and is maintained by the product
If you do not update an association within the duration specified by this parameter, the product removes the association and cleans the table, providing additional space for new entries.
The default is 30-Days.
Anomalous Number of Assoc / Notify Severity
Indicates the severity of the message issued when an "anomalous number of associations" condition is detected on the system
The default is disabled, which indicates that no message is sent.
Number of Assoc Threshold
Threshold for the anomalous number of associations. If the association count for any association item is more than the specified standard deviations away from the average number of associations, this condition is detected and reported.
The default is 3-Stdev.
Number of Assoc Marginal Pct
A secondary threshold for the anomalous number of associations. The number of associations must exceed this percentage of the average (in addition to lying outside the threshold above).
Anomalous Assoc Activity / Notify Severity
Indicates the severity of the message issued when the number of messages associated with a particular association item is greater than the configured threshold
The default is disabled, which indicates that no message is sent.
Assoc Activity Threshold
Threshold for the anomalous association activity. If the number of messages for any association item is more than the specified standard deviations away from the average number of messages, this condition is detected and reported.
The default is 3-Stdev.
Assoc Activity Marginal Pct
A secondary threshold for the anomalous association activity. The number messages for an association must exceed this percentage of the average (in addition to lying outside the threshold above).
The default is 20.
Enable Association ODBC Output
(Deprecated from SPE2410 onwards) determines whether to enable the automatic output of association data to a relational database table and ODBC Data Source, configured below
This provides a simple method of exporting all association data to a relational database for further reporting and analysis.
The default is No.
ODBC Data Source Name
(Deprecated from SPE2410 onwards) (Optional) an ODBC data source name (configured on the Reports > ODBC tab) that will receive the association data
The user must configure the ODBC data source in the Windows control panel as a system DSN, and then configure the value in the Reports > ODBC tab for the data item to appear in this drop-down list.
The default is None.
Database Table Name
(Deprecated from SPE2410 onwards) the database table name that receives the association data
In order to update data into a relational database, you must perform the following steps:
- Enable the Association ODBC Output.
- Select the ODBC Data Source Name.
- Specify a valid Database Table Name in the field.
The default is None and the maximum character limit is 20.
- Click Commit.
Detecting statistical anomalies
The statistical anomaly detection runs at midnight, so that is when any messages indicating an anomalous condition appear unless the facility is specifically bypassed by setting the message severity to disabled for the anomaly detection or setting the threshold to a very high value.
Although these indicators appear similar, they are quite different:
Anomalous Number of Associations—This condition exists when any association item has more than the average number of associations for all items.
- Anomalous Association Item Activity—This condition exists when any association item has more messages than the average number of messages for any item. The message counts are displayed on various screens and indicate how often the association is actually updated on the system. Generally, this might indicate a security risk because the user is generating an exceptional number of messages, indicating a malicious or suspicious act.
When one of these conditions occurs, the system sends a message for each detected condition of the severity specified on the Advanced screen. The exact format of the message appears in Internal-messages.