IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Integrating Solarwinds Orion application logs into QRadar

  • 1.  Integrating Solarwinds Orion application logs into QRadar

    Posted Thu May 20, 2021 09:57 AM

    I am trying to get Logs generated by the Solarwinds Orion application itself into QRadar, currently in the DSM guide i see there is a Solarwinds Orion integration and DSM for a much older version but as far as i understand that is only for sending the alerts and event which the application receives from other systems (i.e. router or servers) and forwarding them to QRadar via SNMP. Is there a more standardized way for getting the logs generated by Solarwinds Orion application and is there a pre built DSM for this



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: Integrating Solarwinds Orion application logs into QRadar

    Posted Fri May 21, 2021 02:18 PM

    The DSM Guide lists QA team validated versions that we have tested and are known to pass review and validation. This does not indicate that the DSM does not work for a product that lists older version information. In Support, we typically tell users to complete the integration as described in the DSM Configuration Guide and open a case for any Official DSMs that do not parse events as expected.

    The DSM Guide outlines the tested standard. You could open an Integration Request for Enhancement to request something like a DSM for Solar Windows Orion Log Viewer (which as a Syslog forward functionality) based on the documentation. However, I'm not sure if this has the capability you are explicitly asking about: https://documentation.solarwinds.com/en/success_center/orionplatform/content/lm/lm-log-forwarding.htm.

    If the Solarwinds Log Viewer sends Syslog and includes the data you are interested in, you should be able to use the DSM Editor to create a custom log source type for your events.

    QRadar RFEs FAQ: https://www.ibm.com/support/pages/qradar-request-enhancements-rfe-and-how-use-them



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: Integrating Solarwinds Orion application logs into QRadar

    Posted Thu May 27, 2021 05:09 AM

    OP I am also looking to do the same. Please inform me if you are able to do it.



    #QRadar
    #Support
    #SupportMigration