Hello all.
Currently, I am trying to integrate a SQL Server 2008 Standard edition to QRadar. Before QRadar Arcsights was used and we used the AuditTrace store procedure given by them. I am evaluating to take trc files to qradar but is needed a transformation before that. I have evaluated the following:
- Creating view referring trc files: no options because we cannot create a view
- Modify current store procedure to save trace files in plain text format: still reviewing but I do not see it feasible
Do you have any recommendations to achieve this?
Thanks!
------------------------------
Andres Arguelles
------------------------------