Crawl IBM Db2 for z/OS
Extract metadata from IBM Db2 for z/OS to catalog databases, schemas, tables, views, columns, stored procedures, and functions in Atlan.
Extract metadata from your IBM Db2 for z/OS subsystem into Atlan to catalog databases, schemas, tables, views, columns, stored procedures, and functions. Atlan also generates lineage from view, stored procedure, and function definitions.
Prerequisites
Before you begin, make sure you have:
- Configured Db2 for z/OS catalog privileges for the Atlan authorization ID
- Db2 connection details: host, DDF listener port, DRDA location name, and credentials
- Reviewed the order of operations for workflow execution
Create crawler workflow
Create a new IBM Db2 for z/OS crawler workflow in Atlan by selecting the connector package, configuring your extraction method and connection details, and running the crawler to extract metadata.
-
In your Atlan workspace, click Connectors in the left sidebar.
- If you are using the Old UI (Classic), click New Workflow in the top navigation.
-
Click Marketplace.
-
Search for IBM Db2 for z/OS Assets and select it.
-
Click Install.
-
Once installation completes, click Setup Workflow on the same tile.
Configure extraction
Select your extraction method and provide the connection details.
- Direct
- Agent
In Direct extraction, Atlan connects to your Db2 for z/OS subsystem and crawls metadata directly.
-
For Host, enter the hostname or IP address of your Db2 DDF listener.
-
For Port, enter the DRDA listener port (default: 446). If your site secures traffic with AT-TLS, this port is often different.
-
For Username, enter the authorization ID you created during setup.
-
For Password, enter the password for the authorization ID.
-
For Location, enter the DRDA location name of the subsystem, for example
DB2LOC. Your Db2 operator can find it with the-DISPLAY DDFcommand. -
If your subsystem requires encrypted connections, set Enable SSL/TLS to Enabled, then provide either a truststore or a certificate:
- For SSL Truststore File, upload the JKS or PKCS12 truststore you prepared during setup.
- For Truststore Password, enter the truststore password. Leave it empty if the truststore has no password.
- For Truststore Type, select PKCS12 or JKS.
- For SSL Server Certificate, upload the server or CA certificate as an
.armor.pemfile instead of a truststore. Leave it empty if you uploaded a truststore.
-
Click Test Authentication to confirm connectivity to Db2 for z/OS.
-
Once authentication is successful, navigate to the bottom of the screen and click Next.
In Agent extraction, Self-Deployed Runtime executes metadata extraction within your organization's environment.
-
Install Self-Deployed Runtime if you haven't already:
-
Select the Agent tab.
-
Store sensitive information, such as the username and password, in the secret store configured with the Self-Deployed Runtime and reference the secret keys in the corresponding fields. For more information, see Configure workflow for SDR mode of execution.
-
If your subsystem requires encrypted connections, set Enable SSL/TLS to Enabled:
- For SSL Truststore File, reference the truststore instead of uploading it - provide either an object store key in your deployment bucket (for example,
objectstore://path/to/truststore.p12) or a secret store path whose value is the base64-encoded truststore. For more information, see Configure file inputs for workflow execution. - For Truststore Password, reference the secret store path whose value is the truststore password. Leave it empty if the truststore has no password.
- For Truststore Type, select PKCS12 or JKS.
- For SSL Server Certificate, reference the
.armor.pemcertificate the same way if you use a certificate instead of a truststore.
- For SSL Truststore File, reference the truststore instead of uploading it - provide either an object store key in your deployment bucket (for example,
-
For details on the remaining fields, refer to the Direct extraction tab.
-
Click Next after completing the configuration.
Configure connection
Set up the connection name and access controls for your Db2 for z/OS data source in Atlan.
-
Provide a Connection Name that represents your source environment. For example, you might use values like
production,development,gold, oranalytics. -
To change the users able to manage this connection, update the users or groups listed under Connection Admins. If you don't specify any user or group, nobody can manage the connection, including admins.
-
Click Next at the bottom of the screen.
Configure crawler
Configure which schemas to include or exclude. If a schema appears in both filters, the exclude filter takes precedence. System schemas (SYSIBM, SYSPROC, SYSSTAT, SYSCTRL, SYSFUN, SYSIBMTS, NULLID, DSNRGCOL, DSNRGNXT, DSNUTILS, DSNTRACE) are excluded automatically.
- Direct
- Agent
-
To select specific schemas for crawling, click Include Schemas. By default, all schemas are included.
-
To exclude specific schemas from crawling, click Exclude Schemas. By default, no schemas are excluded.
In Agent extraction, provide the include and exclude filters as a JSON map of schema-name patterns to a list of object patterns. An empty list selects the whole schema.
-
For Include Schemas, enter the schemas to include. For example,
{"^FINANCE$": []}includes the entireFINANCEschema. By default, all schemas are included. -
For Exclude Schemas, enter the schemas to exclude. By default, no schemas are excluded.
Db2 for z/OS doesn't support regular expression matching in catalog queries, so Atlan renders these filters as exact-match and LIKE predicates. Use % and _ for wildcards rather than regular expression syntax.
Run crawler
- Direct
- Agent
-
To verify permissions and configuration before running, click Preflight checks.
-
Choose your run option:
- To run the crawler once immediately, click Run at the bottom of the screen.
- To schedule the crawler to run hourly, daily, weekly, or monthly, click Schedule Run at the bottom of the screen.
Choose your run option:
- To run the crawler once immediately, click Run at the bottom of the screen.
- To schedule the crawler to run hourly, daily, weekly, or monthly, click Schedule Run at the bottom of the screen.
Once the crawler completes, you can view the assets in Atlan's asset page.
See also
- How Atlan connects to IBM Db2 for z/OS: Connectivity, authentication, and data access patterns
- What does Atlan crawl from IBM Db2 for z/OS: Complete reference of assets and metadata discovered during crawling
- Preflight checks for IBM Db2 for z/OS: Validation checks for permissions and configuration before running the crawler