To create an Amazon AWS S3 REST API Log Source for IBM QRadar, perform the following procedure.

Prerequisites

See Creating a Data Forwarder for IBM QRadar.

Procedure

  1. Sign into the QRadar console.
  2. Go to Admin > QRadar Log Source Management.

    QRadar Log Source Management page in the QRadar console

  3. In the pop-up window, click Log Sources.
  4. Click the +New Log Source button and select Single Log Source.
  5. In the search field, enter and then select Carbon Black Cloud.
  6. Click Step 2: Select Protocol Type.
  7. In the search field, enter and then select Amazon AWS S3 REST API.

    Select Amazon AWS S3 REST API

  8. Click Step 3: Configure Protocol Protocols.
  9. Enter a name for the Log Source in the Name field.
    Note:
    • Choose a different name from the built-in log source CarbonBlackCloudCustom, or you will have difficulties filtering events based on the log source name.
    • The default value for Coalescing Events is Enabled. When a Log Source emits multiple similar events in a short time span, they are aggregated. The event count of the single event reflects the number of events that have been aggregated. This feature reduces the storage cost of events. Disable this option if you want a separate event in QRadar for each alert.
  10. Configure the Protocol Parameters:
    • Log Source identifier - Choose a name for your Log Source.
    • Authentication Method - Access Key ID / Secret Key.
    • Access Key ID and Secret Key - The Access Key and ID that are required to access the AWS S3 Bucket.
    • S3 Collection Method - SQS Event Notification.
    • SQS Queue URL - URL to the queue. This can be copied from the AWS Management Console.
    • Region Name - Use the same value that you used to set up the S3 bucket.
    • Event Format - LINEBYLINE. Data Forwarder generates a jsonl file.

    Enter Log Source parameters

  11. Click Step 5: Test Protocol Parameters to verify the configuration.
  12. In the Admin tab, click Deploy Changes in the Notification pop-up window.

What to do next

Install and Configure the Carbon Black Cloud App for IBM QRadar