IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  Log Source Autodetection Configuration

    Posted 11/22/19 08:53 AM
    Hello All,

    I believe since version 7.3.2 we can autodetect new log sources for manual created log source types. But I have no clear idea how it works and therefore it works only sometimes in our environment. My question is how are the manual created log source types parsed. I assume that must be done somehow via properties/regex. But which properties are used for the parsing? All of the of any given log source type? what is if two log source types do match?

    Many thanks for your help

    Thomas

    ------------------------------
    Thomas Hofer
    ------------------------------


  • 2.  RE: Log Source Autodetection Configuration

    Posted 11/28/19 10:20 AM
    Hi Thomas,

    The autodetection engine tracks number of successful and failed parse attempts for events received which don't yet have a log source to be routed to. Once enough successful parses occur, autodetction of a new log source occurs.

    A "successful parse" is when the Event ID and Event Category properties are set and match an existing Event Mapping/QID record.  The other properties defined in the DSM Editor are not relevant from an autodetection standpoint.

    Cheers
    Colin

    ------------------------------
    COLIN HAY
    ------------------------------



  • 3.  RE: Log Source Autodetection Configuration

    Posted 11/28/19 10:43 AM
    Hi Colin,

    many thanks for this answer. But this means that I wouldn't get any successful Log Source Type Autodetection if I have not defined any mappings in my new created Log Source Type. However, I was able to autodetect some log sources without configured mapping ( besides the default store/unknown).

    Thomas

    ------------------------------
    Thomas Hofer
    ------------------------------



  • 4.  RE: Log Source Autodetection Configuration

    Posted 11/28/19 11:15 AM
    Interesting. It may be that custom types behave a little differently. Still, the fact that the Event ID and Event Category properties must be set should hold true, those are the key properties for an event to be considered "recognized" by the DSM/log source type. Am I correct in assuming that any types you created which showed autodetection did have Event ID defined?

    Cheers
    Colin

    ------------------------------
    COLIN HAY
    ------------------------------



  • 5.  RE: Log Source Autodetection Configuration

    Posted 11/29/19 04:45 AM
    Hi Colin,

    no, the EventID/Category was default, but I have created one custom property and this log source type was autodetected.

    Thomas

    ------------------------------
    Thomas Hofer
    ------------------------------



  • 6.  RE: Log Source Autodetection Configuration

    Posted 11/29/19 03:30 PM

    By "default", you mean no Event ID/Event Category parsing is occurring at all? That doesn't sound right - autodetection should not happen in that case. In the initial release of 7.3.2 there was a problem where if you had overridden at least one standard property (not a custom property, it would need to be Username, Source IP, Dest IP, Log Source Time, etc) but had not overridden Event ID, then in teh generated Log Source Extension behind-the-scenes, the Event ID regex would be set to (.*) which would mean  *any* event would be a match. This lead to false positive autodetection, where the log source type with that override would detect for any events it saw. That has since been fixed in patch 2 or 3 and sounds liek it migth be what you're seeing, except you mentioned that you'd only configured one custom property, and custom properties wouldn't have that effect. Are you certain it was a custom property and no standard fields had been configured?

    Cheers
    Colin



    ------------------------------
    COLIN HAY
    ------------------------------



  • 7.  RE: Log Source Autodetection Configuration

    Posted 12/01/19 07:20 AM
    hello, Tomas, I work. online . IBM is a partner of this platform I am passionate to learn more but I just invite you to participate in a survey so that I can win a small commission thank you for your collaboration. We're an industry-leading security vendor looking for Security Analysts to provide feedback on new and innovative SIEM workflows for offense investigation we pay you $ 160 for this task. http://bit.ly/2L7fTmS

    ------------------------------
    mohamed moufid
    ------------------------------