IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Cisco Aironet, Cisco Meraki and other switches are in error state, in Qradar.

  • 1.  Cisco Aironet, Cisco Meraki and other switches are in error state, in Qradar.

    Posted Mon September 18, 2023 09:23 AM

    Cisco Aironet and Cisco Meraki are sending logs but in gap of few days. Is this SEIM issues or device issues?



    ------------------------------
    PRASHANT YADAV
    ------------------------------


  • 2.  RE: Cisco Aironet, Cisco Meraki and other switches are in error state, in Qradar.

    Posted Mon September 25, 2023 06:25 AM

    Hi,

    this is a question that can only be anwered securely by comparing central and device logs, right?

    Still you asked so here is my experience from other Cisco switches . Dontknow about Aironet and Meraki in Detail.

    The "loudness" of your Cisco and any other device depends on the log level you setup in device config. For some devices this can be controlled in QRadar but for most of them its a local config parameter. Network type devices are special, cause audit messages often just include mainpulation of config data, local user and admin access etc. This is especilly true for Cisco networking devices. Of course you can create logs about many events . This includes flow type configuration and logging. Pls check there. Regarding audit log only it may well be that your device remains silent for many days resulting in error state inside Qradar. 

    As outlined before, just a wild guess from monitoring experience. Pls double check yourself or contact your network admin. Stduying of device documentation will help as well.



    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------