IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SQL Server trace file ingestion

    Posted Fri July 03, 2020 08:24 PM
    Hello all.

    Currently, I am trying to integrate a SQL Server 2008 Standard edition to QRadar. Before QRadar Arcsights was used and we used the AuditTrace store procedure given by them. I am evaluating to take trc files to qradar but is needed a transformation before that. I have evaluated the following:

    • Creating view referring trc files: no options because we cannot create a view
    • Modify current store procedure to save trace files in plain text format: still reviewing but I do not see it feasible
    Do you have any recommendations to achieve this?

    Thanks!

    ------------------------------
    Andres Arguelles
    ------------------------------


  • 2.  RE: SQL Server trace file ingestion

    Posted Thu July 30, 2020 02:58 PM
    Hello all.

    After working with the DBAs I have solved this defining a view using the SQL function fn_trace_gettable. I share with all of you if this could be useful to everyone in the community.

    ------------------------------
    Andres Arguelles
    ------------------------------



  • 3.  RE: SQL Server trace file ingestion

    Posted Wed March 31, 2021 05:39 PM
    Hi Andres,

    Did you get any success with this? Can you please share the details here?

    Thanks

    ------------------------------
    Rameez Ali
    ------------------------------