IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  LinuxOS (TLS) sources intermittent

    Posted 04/06/20 03:07 PM

    Am working on closing out a small project and have run into issues with a small number of linux servers.

    The servers are configured to forward to an event collector on tcp port 6514, and while the traffic can be observed when running tcpdump on the EC - nothing populates in the SIEM and no log sources are generated.

    This is difficult to understand as many other hosts (linux) are successfully forwarding from the same subnet and generating log sources without issue. 

    Any guidance or direction is greatly appreciated.



    ------------------------------
    JG
    ------------------------------


  • 2.  RE: LinuxOS (TLS) sources intermittent

    Posted 04/07/20 12:31 PM
    From the console's UI take a look the EC's event log. These are prefixed by the following name

    SIM Generic Log DSM

    You will have one for each collector, and example name is

    SIM Generic Log DSM-111 :: QRACollector1

    111 being the collector ID and QRACollector1 is the hostname of the collector. 

    Arrange this log source by source IP and compare to the IP addresses of the systems you are missing. If you have information in this location then you would have to create a manual log source and pay attention to the Log Source Identifier and ensure it matches the IP of hostname of sources shown in the above event log.


    Good luck!

    ------------------------------
    JH
    ------------------------------