Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.
Hi,
Has any one successfully added SLES (SUSE Linux Enterprise Server 15) as a log source and will be kind to share the procedure?
BR,
ALEX
I believe that SUSE documentation the procedure as of SUSE V11 to use rsyslogd. See this article for reference. I have not configured SUSE with QRadar, but they previously replaced syslog-ng with rsyslog.
SUSE documentation (recommended): https://www.suse.com/c/how-configure-sles11-cache-and-send-log-events-sentinel-rsyslogd/
Older forum post that also outlines this information: https://www.ibm.com/mysupport/s/question/0D50z00006PEFCD/configure-linux-os-to-send-audit-logs-to-qradar?language=fi
Hi Jonathan,
I had already tried this procedures but without success. That is why i posted, and i can not find what i am missing.