Gateway Log Source Methodologies - Overview
Many QRadar protocol sources that support collecting data streams that potentially contain data from multiple sources support the “Gateway Log Source” parameter. The following protocol sources are:
- Amazon AWS S3 REST API
- Amazon Web Services
- Apache Kafka
- Syslog Redirect (who’s sole purpose is to do this)
- TCP Multiline
- UDP Multiline
This allows you to split the logs back out into multiple log sources even though the data may have been aggregated into a single stream or is being collected by a single log source.
Log sources for the dynamic log source identifiers used are either automatically created (if the target DSM supports Traffic Analysis) or may be manually created with the specific DSM type and as Protocol type Syslog.
Gateway Log Sources can be used in one of 3 models:
Fan:
- One Protocol log source creating or targeting multiple log sources
Funnel:
- Multiple protocol sources feeding a single destination log source
Fan and Funnel (Fannel):
- Implements both the performance aspect of multiple log sources (funnel) with the autocreation or multiple destination log source aspect as well (fan).