To create a Syslog Log Source for IBM QRadar, perform the following procedure.
Procedure
- Open the QRadar console.
- Go to Admin > QRadar Log Source Management.
- In the pop-up window, click Log Sources.
- Select Single Log Source.
- In the search field, enter and select
Carbon Black Cloud
.
- Click Step2: Select Protocol Type.
- In the search field, enter and select
Syslog
.
- Click Step3: Configure Log Source Parameters.
- Enter a unique
Name
and optionally change predefined parameters.
Note:
The default value for Coalescing Events is Enabled
. Coalescing Events means that when a log source emits multiple similar events in a short time span, they are aggregated. The event count of the single event reflects the number of events that have been aggregated. This feature reduces the storage cost of events. If you want separate events in QRadar for similar alerts, you can disable this option.
- Click Step 4:Configure Protocol Parameters.
- Enter a unique
Log Source Identifier
and click Finish.
- In the Notification pop-up window in the Admin tab, click Deploy Changes.
- Enter the
Log Source Identifier
from Step 11.