IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  F5 Integration With QRadar

    Posted Thu April 25, 2024 01:58 AM

    Hi,

    I have configured a F5 log source in QRadar, the logs are successfully sending from the F5 device but not reaching to the QRadar.

    Verified in the unknown logs as well but not available.

    F5 Version: 17.x

    QRadar Version: 7.5.0 UP6

    Please assist me to resolve the issue.

    Thanks



    ------------------------------
    Arunkumar R
    ------------------------------


  • 2.  RE: F5 Integration With QRadar

    Posted Thu April 25, 2024 09:10 AM

    Hi Arunkumar

    Are you seeing any errors?  Does a TCP dump show the events arriving at QRadar?

    Can you see any events with the same source IP?

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 3.  RE: F5 Integration With QRadar

    Posted Fri April 26, 2024 02:42 AM

    Hi John,

    No errors, and still no events received.

    Yes, the TCP dump shows the events that arrive to QRadar.

    I could see the firewall events for this IP address.

    Thanks



    ------------------------------
    Arunkumar R
    ------------------------------



  • 4.  RE: F5 Integration With QRadar

    Posted Fri April 26, 2024 07:24 AM

    Hi Arunkumar,

    I would suggest opening a case with support so we can review the configuration and the logs.

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 5.  RE: F5 Integration With QRadar

    Posted Fri April 26, 2024 08:53 AM

    Couple of things, F5 events have huge payloads, so make sure to use TCP not UDP.  We also recommend the syslog payload limit be changed in setup to around 32K, with huge UDP support those can go larger as well. The F5 admins need to make sure they have the logging set in multiple place, just follow the IBM docs.  



    ------------------------------
    Frank Eargle
    ------------------------------