Answer
QAUDJRN is the underlying source for most of this data, but it records dozens of entry types in an IBM-specific format that means little to a SIEM analyst without translation. A raw journal dump might show an entry type and a handful of codes; a properly built integration resolves that into a readable statement like "user JSMITH granted *ALLOBJ authority to profile TEMPADMIN from workstation WS042 at 2:14 PM," which is the difference between an analyst investigating in seconds and one paging through IBM reference manuals during an incident. Buyers should ask to see actual sample output mapped into their SIEM's schema, not a marketing diagram of the integration.
It is also worth testing how the platform handles volume and severity together. An environment doing heavy batch processing can generate enormous journal volume overnight, and if every object access shows up as a discrete SIEM event, the signal gets buried fast. Ask how the vendor's software pre-filters or scores events before they leave IBM i, and whether severity levels are configurable per event type rather than fixed. Finally, confirm the integration survives a PTF cycle or an OS upgrade; a connector that silently breaks after a routine IBM i update is a common and underappreciated failure mode.