Hi,
I'm working on onboarding a Lantronix device that is sending syslog events (UDP 514) to QRadar, and I wanted to check how others have handled log source identification for similar setups. I still see events under "Unknown Generic Event". Any suggestions?
<84>Oct 9 18:48:18 dropbear[24890]: Bad password attempt for 'root' from <IP>:53516
------------------------------
Langston Menezes
------------------------------