IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Microsoft Azure - Event Hub Dont get the log

    Posted Sun September 08, 2019 01:25 PM
    hey Guys,

    about two week we trying to connect Microsoft azure event hub.

    we do everything like the IBM manual about the azure configuration and qradar configuration.

    do you have any other idea who to solve this ? 


    maybe we miss somthing.



    ------------------------------
    nati nakache
    ------------------------------


  • 2.  RE: Microsoft Azure - Event Hub Dont get the log

    Posted Tue September 24, 2019 12:08 PM
    It's currently broke.   A new DSM is supposedly in the works between IBM & M$ devs.

    ------------------------------
    Troy Barnhart
    ------------------------------



  • 3.  RE: Microsoft Azure - Event Hub Dont get the log

    Posted Tue October 08, 2019 09:58 PM
    Hi Troy,

    Can you be more specific about what you feel is broken in the Azure Event Hub Protocol?

    We are working on various improvements but the current version in the field is working well for many customers - I'd hate for @nati nakache to think things are just completely broken and that they should wait for something new!​​

    ------------------------------
    Chris Collins
    ------------------------------



  • 4.  RE: Microsoft Azure - Event Hub Dont get the log

    Posted Wed October 09, 2019 12:00 PM
    The Microsoft Graph Security API Events for the Off365/AzureAD side that feed thru the Azure DSM Event Hubs, instead of the Off365 DSM.

    ------------------------------
    Troy Barnhart
    ------------------------------



  • 5.  RE: Microsoft Azure - Event Hub Dont get the log

    Posted Mon October 14, 2019 02:44 AM
    Hi,
    You can enable debug log on a qradar for azure, steps that are listed here: https://developer.ibm.com/answers/questions/489390/azure-event-hub-integration-nothing-on-the-logs/

    After that you can check the log file. It helped me to understand that problem was in event hub configuration. Particular in "Firewall and Networks" settings.

    ------------------------------
    Arturs Garmasovs
    ------------------------------