Hello @Alexandr Martyniuk,
i see you have a McAfeeWebGW connected to the QRadar via Syslog? Can you give me a tip on how this was done? The original DSM cannot parse the events in our case. How is it possible to change the format from CEF to LEEF? Thank you in advance!
------------------------------
Timo Lüllmann
------------------------------
Original Message:
Sent: Thu February 29, 2024 06:27 AM
From: Alexandr Martyniuk
Subject: Empty requests from Qradar Console via proxy
Hello,
Thank you for reply. I'd like to clarify. McAfee WG is a log source in our SIEM and we added it deliberately.
I just don't understand the reason why SIEM makes those requests via proxy. As you can see in event payload example from original post source and destination of the request is Qradar Console itself.
I will be very grateful, if someone explains me such behavior of Console. Is it ok, or caused by some misconfiguration?
------------------------------
Alexandr Martyniuk
------------------------------
Original Message:
Sent: Tue February 27, 2024 05:57 PM
From: MIAN SALAHUDDIN
Subject: Empty requests from Qradar Console via proxy
Hi Alexandr,
Your McAfee Web Gateway Proxy Server is erroneously identified as a Log Source for event collection. Here are a couple of options to address this issue:
- Look into whether there's an Auto Discovered Log Source created for it. if YES, consider disabling it.
- Experiment with turning off syslog logging on the McAfee Web Gateway Server and observe the outcomes. It will establish the assumption.
If the issue persists, I recommend opening a case with IBM Support to further investigate your environment. Cheers.
Best regards,
Kashif
------------------------------
MIAN SALAHUDDIN