IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Sophos Entreprise Console and Qradar integration

  • 1.  Sophos Entreprise Console and Qradar integration

    Posted Wed December 02, 2020 09:28 AM
    Hello All,

    I try to send events from my Sophos Entreprise console to my Qradar server using JDBC connector but I gor the error below, if any one did this kind of integration please help

    Dec 2 15:08:01 ::ffff:10.100.48.10 [ecs-ec-ingress.ecs-ec-ingress] [Thread-233206] com.q1labs.semsources.sources.j dbcsophos.JdbcSophosEventConnector: [WARN] [NOT:0000004000][QRADARIP/- -] [-/- -]Network error IOException: jav a.security.cert.CertificateException: Server certificate not recognized on MSDE/SOPHOS/SOPHOS552@XX.XX.XX.XX

    Dec 2 15:08:24 ::ffff:QRADARIP [ecs-ec-ingress.ecs-ec-ingress] [MSDE/SOPHOS/SOPHOS552@XX.XX.XX.XX Protocol Provider Thread: class com.q1labs.semsources.sources.jdbcsophos.JdbcSophosEventConnector834] com.q1labs.semsources.sources.jdbcsophos.JdbcSophosEventConnector: [ERROR] [NOT:0000003000][QRADARIP/- -] [-/- -]connect failed on MSDE/SOPHOS/SOPHOS552@XX.XX.XX.XX Protocol Provider Thread: class com.q1labs.semsources.sources.jdbcsophos.JdbcSophosEventConnector834

    Dec 2 15:08:24 ::ffff:QRADARIP [ecs-ec-ingress.ecs-ec-ingress] [MSDE/SOPHOS/SOPHOS552@XX.XX.XX.XX Protocol Provider Thread: class com.q1labs.semsources.sources.jdbcsophos.JdbcSophosEventConnector834] com.q1labs.semsources.sources.jdbcsophos.JdbcSophosEventConnector: [WARN] [NOT:0000004000][QRADARIP/- -] [-/- -]Connection attempt has failed and connection will be retried at regular intervals.

    ------------------------------
    cherbani samir
    ------------------------------