Hello
I am brand new to QRadar. I have been tasked with pulling logs from Azure Log Analytics Workspace to QRadar. The group using the Analytics Workspace is not using the Azure Event Hub. They are requesting we pull the logs as syslog in to QRadar. I have created a log source with the Log Source Type Microsoft Azure Platform and the Protocol Type of Syslog. However no events are pulling in. I have tried to update the source to be a Log Source Type of Universal DSM and Protocol Type of Syslog and still no events are pulling in.
Has anyone completed this type of configuration? If so, would you be able to shed some light on how to complete this setup? I have not had to setup a log source yet so the more detail, the better.
Thank you!
Jeannie
------------------------------
Jeannie Burrell
------------------------------