IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only

Log file Protocol Configuration

  • 1.  Log file Protocol Configuration

    Posted 04/14/23 10:33 AM

    Hello,
    we want to get logs from an AS/400 instance, so we followed the procedure described in the documentation and uploaded these logs onto a FTP server.
    From here, we should import them into Qradar using SFTP, I am following the instructions in https://www.ibm.com/docs/en/dsm?topic=options-log-file-protocol-configuration

    The following point is not clear:

    If the system is configured to use key authentication, type the SSH key. When an SSH key file is used, the Remote Password field is ignored.

    The SSH key must be located in the /opt/qradar/conf/keys directory.


    We have no "keys" directory inside /opt/qradar/conf on the event processor that should ingest the logs. So, once we get the public key of the target SFTP server, where should we place it?

    B Regards

    Davide



    ------------------------------
    Davide Salardi
    ------------------------------