IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  managed wincollect with qradar event collector

    Posted Tue January 30, 2024 08:21 AM

    Dears,

    i have event collector and i need to sent it's logs to collector , how can that happen and how configure the destination on wincollection



    ------------------------------
    osama ahmed
    ------------------------------


  • 2.  RE: managed wincollect with qradar event collector

    Posted Fri February 02, 2024 03:50 AM

    Hi Osama,

    this seems to be the informations you are looking for: https://www.ibm.com/docs/en/qradar-common?topic=installations-managed-wincollect

    Here an additional source with very helpful informations further on.. 

    https://www.ibm.com/community/101/qradar/wincollect/

    Regards,

    Ralph



    ------------------------------
    Ralph Belfiore
    SIEM Expert
    connecT SYSTEMHAUS AG
    Siegen
    +491726365525
    ------------------------------



  • 3.  RE: managed wincollect with qradar event collector

    Posted Sat February 03, 2024 09:12 AM

    Dear Ralph ,

    the managed wincollect need to create (Destination - a token  ) ,

    so the Destionation is created on Console and i need to log source to send logs to collector not the console



    ------------------------------
    osama ahmed
    ------------------------------



  • 4.  RE: managed wincollect with qradar event collector

    Posted Mon February 05, 2024 02:46 AM

    Hi Osama,

    i think here you'll find the answer to your question: https://www.ibm.com/docs/en/qradar-common?topic=installations-adding-multiple-destinations-wincollect-agents

    And additonal to it, this one as well: https://www.ibm.com/docs/en/qradar-common?topic=installations-installing-wincollect-agent-windows-host

    Regards,

    Ralph



    ------------------------------
    Ralph Belfiore
    SIEM Expert
    connecT SYSTEMHAUS AG
    Siegen
    +491726365525
    ------------------------------