Hi all,
So I've downloaded the QRadar community edition and I'm trying to understand how it works.
As my first test after installing it is that I installed the Log Source Management plugin and I want to consume syslog messages pushed from a Juniper vSRX.
I set up a single log source with the hostname of the device as the unique identifier
However all the events are being recorded as: Juniper Networks Routing Platform Message
So for example if I have this syslog message:
<27>Apr 6 16:51:58 <MyDeviceHostname> rmopd[27262]: RMOPD_ICMP_SENDMSG_FAILURE: sendmsg(ICMP): No route to host
It gets parsed incorrectly as an IDP event
And this happens to every event that occurs
However when I open the extract properties option there is this browse event name option:
So I think it's unreasonable for me to set the format correctly for every message.
Any ideas why it's not parsing the message correctly? Is there some configuration I've missed?
I'm assuming it's matching the incorrect QID as seen below from the same event:
------------------------------
Jonathan Nakandala
------------------------------