IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Parsing and Event Mapping

    Posted Fri March 05, 2021 08:24 AM

    We have a customized DSM for CheckPoint log source, where we are collecting Admin logs, for most of the CheckPoint GAIA Embedded log sources, we are getting logs as Unknown. While checking in DSM editor, it is showing as Parsed and Mapped, but there is no logs in the log source. What could be the issue?



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: Parsing and Event Mapping

    Posted Fri March 05, 2021 08:53 AM

    Hello Arul,

    Check if you have done the QID mapping correctly. Follow :

    https://www.ibm.com/support/pages/creating-custom-dsm

    Thanks,

    Ashish



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: Parsing and Event Mapping

    Posted Sat March 06, 2021 07:25 AM

    Hello Arul.

    This could be also helpful for event parsing.

    QRadar Parsing - Introduction

    https://www.youtube.com/watch?v=MP6grxJvxn0

    QRadar DSM Editor Tutorial Part One

    https://www.youtube.com/watch?v=LRhNMejQFNM

    QRadar DSM Editor Tutorial in less than 10 minutes

    https://www.youtube.com/watch?v=KF40bba_kp0

    QRadar Parsing - Stored and Unknown

    https://www.youtube.com/watch?v=GgPW5OVwoMY

    Thanks.

    Brian.



    #QRadar
    #Support
    #SupportMigration


  • 4.  RE: Parsing and Event Mapping

    Posted Wed June 23, 2021 04:10 PM

    Hello Arul,

    did you solve your issue? I have a similar problem. In DSM the events are Status: "Parsed and mapped", Event ID, Event Category and Event Name are filled out, but in Log view EventID and Event Category are shown as "N/A". In Event Detail view they are shown as "null". I discovered that problem because Identity Information was nut updated. The DSM i used i had to do an overwrite for the EventID because it was not parsed in the original DSM. I did an overwrite of the Event Category and then the Identity information was working at least, but Event ID and Event Category are still null. The event Name is correct and i also did a remapping to a newly created QID the event name changes correctly but the problem with the Event ID and Category persists.

    Thanks

    Martin



    #QRadar
    #Support
    #SupportMigration