BMC AMI Security
Mainframe SIEM and security-event correlation product family from BMC, built on the zDefender technology BMC acquired with CorreLog in 2018.
Visit Website ↗ + Add to CompareOverview
BMC AMI Security is BMC Software’s mainframe security monitoring and event-correlation product family, aimed at getting IBM z/OS security events (RACF, CICS, Db2, DFSMS access attempts and failures) into the same real-time view as an organization’s distributed-systems SIEM. Its lineage traces to CorreLog, an independent SIEM vendor that built its zDefender product specifically to solve a persistent enterprise problem: mainframe security data traditionally lives in its own silo, disconnected from the SIEM and SOC tooling that monitors everything else. BMC acquired CorreLog in October 2018 and has since folded its mainframe capabilities into the BMC AMI Security line, while continuing to sell most of CorreLog’s Windows/Unix distributed products separately.
The current product family includes BMC AMI Command Center for Security (dashboards and SIEM correlation across RACF/CICS/DFSMS/Db2 events), BMC AMI Datastream (real-time delivery of mainframe access data to distributed SIEM platforms such as Splunk, IBM QRadar, and LogRhythm), and BMC AMI Defender (automated configuration-vulnerability scanning based on real-world penetration-test findings). This gives security teams a way to treat the mainframe as a first-class citizen in enterprise-wide threat detection and compliance reporting rather than a system they audit separately once a quarter.
Because this profile covers a specific product line inside BMC — a large, diversified enterprise software company whose broader business spans IT service management, automation, and mainframe modernization well beyond security — the scoring here is scoped to the mainframe security/SIEM capability itself rather than to BMC as a whole. For CISOs running z/OS environments, the practical value is straightforward: it closes a well-known, long-standing blind spot between mainframe and distributed security monitoring.
Innovation Matrix Assessment
BMC has continued to release updates to the AMI Security/AMI Command Center line since the 2018 CorreLog acquisition, integrating it with its broader AMI mainframe portfolio, but the pace reflects a mature enterprise product line's release cadence rather than a fast-moving startup roadmap.
The product is designed to run on-premises on the mainframe and stream events out to existing distributed SIEM platforms, which fits how mainframe shops actually operate, though onboarding still requires the specialized z/OS expertise that is a known industry-wide staffing constraint.
Being embedded inside BMC's large existing mainframe customer base gives this product line reach that an independent CorreLog never had, but there is limited independent evidence of net-new adoption specifically attributable to the security product versus BMC's broader AMI mainframe suite.
Real-time correlation of mainframe security events (RACF, Db2, CICS) into standard SIEM platforms addressed a genuine, long-standing blind spot when CorreLog originally built it; the approach is now well established rather than novel, but remains one of relatively few dedicated options in the mainframe SIEM-bridge niche.
BMC AMI Security has documented integrations with major SIEM platforms (Splunk, QRadar, LogRhythm, ArcSight) and BMC AMI Defender's scanning logic is based on real penetration-test findings rather than only theoretical policy checks, which is a genuine, checkable technical claim, though independent efficacy benchmarking specific to this product was not found.
Mainframes remain core infrastructure for banking, insurance, and government, and the gap between mainframe security auditing and mainstream SIEM/SOC visibility is a persistent, well-documented compliance and detection risk that this product line directly addresses.
Why CISOs Should Care
For any CISO whose organization still runs IBM z/OS for core transaction processing, BMC AMI Security closes the common gap between mainframe security events and the SIEM/SOC tooling used for everything else, reducing the risk of mainframe-side incidents going unnoticed by the main security operations team.
What Makes It Different
Its specific focus on real-time mainframe-to-SIEM event streaming (RACF, Db2, CICS, DFSMS) differentiates it from generic SIEM platforms that only ingest distributed-systems logs and treat mainframe data as an afterthought, if they support it at all.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
As a scoped product line within a much larger, diversified BMC portfolio, BMC AMI Security is a credible, well-integrated answer to a real and specific problem -- mainframe security blind spots -- rather than a disruptive new entrant, and its value is concentrated among the shrinking but still significant population of z/OS-dependent enterprises.
Editorial Note: Claims vs. Verified Findings
This profile is scoped specifically to BMC's mainframe security/SIEM product line (originally CorreLog's zDefender technology), not to BMC Software as a whole, which is a large diversified IT management vendor outside this site's scope. Independently verifiable facts used here are the October 2018 BMC acquisition of CorreLog and BMC's own published product family structure (AMI Command Center for Security, AMI Datastream, AMI Defender); specific efficacy and adoption statistics beyond that are BMC's own marketing and were not independently re-verified.
Sources
Alternatives to BMC AMI Security
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Anvilogic
Palo Alto-based AI security operations platform that automates SOC detection engineering across existing SIEMs and data lakes without…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…