Hi everyone,
I'm setting up log forwarding from Linux servers to QRadar and trying to decide on the best approach from both a security and efficiency standpoint.
Sending all logs gives full visibility, but it creates a lot of noise and increases EPS. On the other hand, limiting to just authpriv or auditd keeps things cleaner, but I'm concerned about missing useful data.
What's considered best practice here? Do you forward everything, or only specific logs like auth, auditd, sshd, etc.? I'm aiming for a setup that catches key security events without overwhelming the SIEM.
Would really appreciate hearing how others have handled this in production.
------------------------------
Fariz Pirmatov
------------------------------