IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QRADAR and Managed Cisco Umbrella

    Posted Thu February 28, 2019 07:36 AM
    Hello All,

    We have a managed DNS service with Cisco (Umbrella) and this is administered by them.

    We receive DNS logs at intervals to a network share on our network but these compressed files contain a CSV file without headers.

    I was looking at using a custom universal DSM with SMB protocol and then use a log source extension.

    Has anyone managed to ingest Cisco Umbrella Logs from a managed service perspective and if yes, what was your approach please?

    Thank you.

    ------------------------------
    Shjajad Ashraf
    ------------------------------


  • 2.  RE: QRADAR and Managed Cisco Umbrella

    Posted Thu February 28, 2019 10:24 AM
    Edited by Jonathan Pechta Thu February 28, 2019 10:26 AM

    Can they put these files in an S3 bucket? If yes, this is the recommended method of consuming these logs in QRadar. I will note that CSV is heavy regex/parsing-wise because you are counting in commas to identify what you need to retrieve to parse values from the payload, but it is definitely possible and there is a write-up on this.

    Cisco has a good integration article here: https://support.umbrella.com/hc/en-us/articles/231248488-Configuring-QRadar-for-use-with-Cisco-Umbrella-Log-Management-in-AWS-S3

    If they can put this info in an S3 bucket, you should be able to grab the data. The Cisco write-up covers the setup in detail, along with the LSX required to do this integration. Not sure if this answers your question from an MSP perspective, but having read only access on an S3 bucket and following the linked setup is likely the best way to get this data.



    ------------------------------
    Jonathan Pechta
    QRadar Support Content Lead

    Official Support forums: https://ibm.biz/qradarforums
    ------------------------------



  • 3.  RE: QRADAR and Managed Cisco Umbrella

    Posted Fri March 01, 2019 01:51 PM
    Thank you for your reply Jonathan.

    I set up the AWS S3 and had the Cisco Umbrella Managed log services to dump the logs into this - which works.

    However, after setting up the log source using the Cisco Umbrella DSM and configuring the settings, the following error is displayed:
    https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.2.7/com.ibm.qradar.doc/38750057.html

    And an extract of the qradar logs:
    There appears to be a configuration issue with the provider connection 'class com.q1labs.semsources.sources.amazonawsrest.AmazonAWSRESTProvider155'.

    I have recreated the log source and also used a trial instance of AWS S3 but still have the same issue.

    Any one had a similar challenge?

    Thank you.

    ------------------------------
    Shjajad Ashraf
    ------------------------------



  • 4.  RE: QRADAR and Managed Cisco Umbrella

    Posted Fri March 29, 2019 08:04 PM
    There is a fix for this... overall, but I would pressure those at Cisco to help alleviate the burden being seen in managed buckets...  If you use your own S3, the fix is working I received today.  However, there is an Access issue with the Managed Instance.  I will update later what I learn.

    Basically as of a month or so ago, the Cisco Umbrella folks added "Blocked Categories" to the log source as well as what appears to be a forced UTC time.  This is why the logs stopped functioning.  The new AWSAPI Protocol is working and I'm now able to see the logs.  In fact, it is much faster than previous PROTOCOLs..

    ------------------------------
    Charles Senne
    ------------------------------



  • 5.  RE: QRADAR and Managed Cisco Umbrella

    Posted Tue April 09, 2019 07:48 AM
    Hello Charles,

    Yheah we were offered the fix from IBM Support but it was an Alpha release and unsupported.  We didn't wan't take the risk.  Good to see you got it to work.

    Have you had any other challenges?

    Thank you.

    ------------------------------
    Shjajad Ashraf
    ------------------------------



  • 6.  RE: QRADAR and Managed Cisco Umbrella

    Posted Tue April 16, 2019 01:38 AM
    Hello Charles,

    I'm getting some errors parsing the Umbrella logs pulled from an S3 bucket, it appears the LSX documented on Cisco's site is now outdated.

    Did the fix you received and tested involved updating the LSX associated to the Umbrella Log Source? Could you (are you able to) share it here?


    Thanks in advance for your help!


    ------------------------------
    Jorge Mora
    ------------------------------



  • 7.  RE: QRADAR and Managed Cisco Umbrella

    Posted Tue April 16, 2019 01:52 AM
    Jorge. The DSM and Protocol updates are available on Fix Central .

    The fix did in fact correct the issues seen with connecting as well as parsing the new "Blocked Categories"

    ------------------------------
    Charles Senne
    ------------------------------