IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Linux os Parser Issue

    Posted Thu February 27, 2025 07:25 AM

    Hi guys,

    Logs coming from Linux os sources are not parsed by default. Normally linux logs should be parsed directly by the system, right? Is there any point we should check about this situation?

    Thank you



    ------------------------------
    Adem Güler
    ------------------------------


  • 2.  RE: Linux os Parser Issue

    Posted Thu February 27, 2025 09:53 AM

    Hi Adem

    I would review the documentation regarding Linux OS logs to ensure the events are of a supported type and that it has been configured correctly

    https://www.ibm.com/docs/en/security-qradar/log-insights/saas?topic=linux-os

    If all of this is correct then you should open a support case.

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 3.  RE: Linux os Parser Issue

    Posted Thu February 27, 2025 10:34 AM

    Hi,

    Actually, we get the logs with rsyslog, so I think there should be no need for a different process. If anyone has encountered it before, I would like to get suggestions.

    Thanks



    ------------------------------
    Adem Güler
    ------------------------------



  • 4.  RE: Linux os Parser Issue

    Posted Sat March 08, 2025 01:47 PM

    Hi,

    I suggest you do following activities:

    1 - check Linux version and dsm compatibility first.

    2 - are these logs from Linux device only or are dumped by some other devices (shortly are you using Linux device as a log collector?)

    3 - check consistency of logs. If not consistent then dsm will not parse it automatically.

    4 - check and update dsm version if possible. (Don't try to delete or reinstall dsm.)

    5 - check in dsm, auto detection is enabled or not.



    ------------------------------
    Abdul Quadeer
    ------------------------------