Hello,
we want to get logs from an AS/400 instance, so we followed the procedure described in the documentation and uploaded these logs onto a FTP server.
From here, we should import them into Qradar using SFTP, I am following the instructions in https://www.ibm.com/docs/en/dsm?topic=options-log-file-protocol-configuration
The following point is not clear:
If the system is configured to use key authentication, type the SSH key. When an SSH key file is used, the Remote Password field is ignored.
The SSH key must be located in the /opt/qradar/conf/keys directory.
We have no "keys" directory inside /opt/qradar/conf on the event processor that should ingest the logs. So, once we get the public key of the target SFTP server, where should we place it?
B Regards
Davide
------------------------------
Davide Salardi
------------------------------