IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Database log source integration IBM Qradar issues

    Posted Wed April 24, 2024 09:04 AM

    Hi Team,
    Database logs are stored in binary format on server. 
    is it possible to integrate IBM Qradar with these binary log sources ? if yes, kindly help me with process.
    Below are the Server OS and  DB details.
    Windows(Maria/Postgre)
    Linux (Maria, postgre and MYSQL)



    ------------------------------
    Anurag Patel
    ------------------------------


  • 2.  RE: Database log source integration IBM Qradar issues

    Posted Tue April 30, 2024 02:47 AM

    Hello Anurag,

    There is no tool which can read the binary format logs. You need to find someway to populate it in event / log format so that later those can be send 
    Whether any of these logs are part of database it self or whether same logs can be populated in any table ? If yes. then you can use JDBC protocol.
    https://www.ibm.com/docs/sr/dsm?topic=labs-jdbc-protocol-configuration-options




    ------------------------------
    Vishal Tangadkar
    IBM Software Support
    IBM INDIA PVT LTD
    ------------------------------



  • 3.  RE: Database log source integration IBM Qradar issues

    Posted Tue April 30, 2024 11:02 AM

    Thank you for your input.

    These logs are database itself.

    Can we do anything from DB server side... I mean can we convert these binary logs to readable/plaintext format?



    ------------------------------
    Anurag Patel
    ------------------------------



  • 4.  RE: Database log source integration IBM Qradar issues

    Posted Mon May 06, 2024 01:54 AM

    Hello Anurag,

    Nope nothing can be done from QRadar side as well which will do the conversion. 



    ------------------------------
    Vishal Tangadkar
    IBM Software Support
    IBM INDIA PVT LTD
    ------------------------------



  • 5.  RE: Database log source integration IBM Qradar issues

    Posted Mon May 06, 2024 05:29 AM

    Thank you so much .



    ------------------------------
    Anurag Patel
    ------------------------------