IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Azure Monitor Log format

    Posted Fri October 28, 2022 09:03 AM
    Microsoft is End of Life support for all diagnostic agents and only will support the Azure Monitor Agent after August 2024.  The JSON format of the Azure Monitor Agent (AMA) is different then the format that the diagnostic agents send.  There is a Request for Enhancement to create a DSM for AMA, QROC-I-52. 
    Need DSM for Azure Monitor Agent Logs
    Ibm remove preview
    Need DSM for Azure Monitor Agent Logs
    View this on Ibm >


    Please go vote for the RFE.  Has anyone created their own custom DSM to parse these logs?


    ------------------------------
    Korry Bradley
    ------------------------------