What about syslog, I have the syslog daemon running and collecting FTP info. Here is a sample. There are some secure and some not secure connections. IP addresses and Userid changed to protect the innocent. There is also more detailed info in the debug.log file.
Jun 1 13:50:26 JESH01 ftps[50332413]: EZYFS56I ID=FTPD100042 ACCESS OK USERID=S999XXX Jun 1 14:03:33 JESH01 ftpd[67109629]: EZYFS50I ID=FTPD100043 CONN starts Client IPaddr=999.19.1.26 hostname=UNKNOWN Jun 1 14:03:33 JESH01 ftps[67109629]: EZYFS56I ID=FTPD100043 ACCESS OK USERID=S999XXX Jun 1 14:13:12 JESH01 ftpd[83886845]: EZYFS50I ID=FTPD100044 CONN starts Client IPaddr=999.19.1.26 hostname=UNKNOWN Jun 1 14:13:12 JESH01 ftps[83886845]: EZYFS56I ID=FTPD100044 ACCESS OK USERID=S999XXX Jun 1 14:28:15 JESH01 ftpd[16777978]: EZYFS50I ID=FTPD100045 CONN starts Client IPaddr=999.19.1.26 hostname=UNKNOWN Jun 1 14:28:15 JESH01 ftps[16777978]: EZYFS56I ID=FTPD100045 ACCESS OK USERID=S999XXX Jun 1 14:33:21 JESH01 ftpd[50332410]: EZYFS50I ID=FTPD100046 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:21 JESH01 ftps[50332410]: EZYFS54I ID=FTPD100046 SECURE OK Mechanism=TLS-P Jun 1 14:33:21 JESH01 ftps[50332410]: EZYFS56I ID=FTPD100046 ACCESS OK USERID=S888XXX Jun 1 14:33:21 JESH01 ftps[33555198]: EZYFS52I ID=FTPD100046 CONN ends Input=0 bytes Output=0 bytes Jun 1 14:33:28 JESH01 ftpd[50332414]: EZYFS50I ID=FTPD100047 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:28 JESH01 ftps[50332414]: EZYFS54I ID=FTPD100047 SECURE OK Mechanism=TLS-P Jun 1 14:33:28 JESH01 ftps[50332414]: EZYFS56I ID=FTPD100047 ACCESS OK USERID=S888XXX Jun 1 14:33:28 JESH01 ftps[767]: EZYFS52I ID=FTPD100047 CONN ends Input=0 bytes Output=0 bytes Jun 1 14:33:30 JESH01 ftpd[16777983]: EZYFS50I ID=FTPD100048 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:30 JESH01 ftps[16777983]: EZYFS54I ID=FTPD100048 SECURE OK Mechanism=TLS-P Jun 1 14:33:30 JESH01 ftps[16777983]: EZYFS56I ID=FTPD100048 ACCESS OK USERID=S888XXX Jun 1 14:33:31 JESH01 ftpd[16777985]: EZYFS50I ID=FTPD100049 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:31 JESH01 ftps[16777985]: EZYFS54I ID=FTPD100049 SECURE OK Mechanism=TLS-P Jun 1 14:33:31 JESH01 ftps[16777985]: EZYFS56I ID=FTPD100049 ACCESS OK USERID=S888XXX Jun 1 14:33:32 JESH01 ftps[67109626]: EZYFS52I ID=FTPD100049 CONN ends Input=0 bytes Output=0 bytes Jun 1 14:33:35 JESH01 ftpd[33555202]: EZYFS50I ID=FTPD100050 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:36 JESH01 ftps[33555202]: EZYFS54I ID=FTPD100050 SECURE OK Mechanism=TLS-P Jun 1 14:33:36 JESH01 ftps[33555202]: EZYFS56I ID=FTPD100050 ACCESS OK USERID=S888XXX Jun 1 14:33:36 JESH01 ftps[771]: EZYFS52I ID=FTPD100050 CONN ends Input=0 bytes Output=0 bytes Jun 1 14:33:39 JESH01 ftpd[83886846]: EZYFS50I ID=FTPD100051 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:39 JESH01 ftps[83886846]: EZYFS54I ID=FTPD100051 SECURE OK Mechanism=TLS-P Jun 1 14:33:39 JESH01 ftps[83886846]: EZYFS56I ID=FTPD100051 ACCESS OK USERID=S888XXX Jun 1 14:33:39 JESH01 ftps[50332419]: EZYFS52I ID=FTPD100051 CONN ends Input=0 bytes Output=0 bytes Jun 1 14:33:42 JESH01 ftpd[50332417]: EZYFS50I ID=FTPD100052 CONN starts Client IPaddr=999.19.1.18 hostname=UNKNOWN Jun 1 14:33:42 JESH01 ftps[50332417]: EZYFS54I ID=FTPD100052 SECURE OK Mechanism=TLS-P Jun 1 14:33:42 JESH01 ftps[50332417]: EZYFS56I ID=FTPD100052 ACCESS OK USERID=S888XXX -----Original Message----- From: IBM Mainframe Discussion List [mailto:IBM-MAIN@LISTSERV.UA.EDU] On Behalf Of venkat kulkarni Sent: Sunday, May 28, 2017 4:17 AM To: IBM-MAIN@LISTSERV.UA.EDU Subject: SMF record for FTP Hello All, We are in the process of converting FTP jobs to SFTP and many of the jobs are converted. But before blocking port 23 for FTP, we want to make sure that all jobs are running with SFTP. Is it possible to collect some SMF record, which can indicate the current running jobs that are still using FTP. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN ========================== This email, and any files transmitted with it, is confidential and intended solely for the use of the individual or entity to which it is addressed. If you have received this email in error, please notify the system manager. This message contains confidential information and is intended only for the individual named. If you are not the named addressee, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this message by mistake and delete this e-mail from your system. If you are not the intended recipient, you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN