IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  UDP max syslog payload length setting for managed host not working

    Posted 01/19/22 10:15 AM

    Hello,

    I try to collect events using WinCollect via UDP, so I changed the system settings (advanced view) for max syslog UDP packet length to 4096.

    Unfortunately the setting seems not to be active for WinCollect destinations on managed hosts, windows events coming to the managed host are still truncated after 1024 bytes. Am I missing something or is there a separate setting for this on the managed host (log collector)?

    Thank you

    Stefan



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: UDP max syslog payload length setting for managed host not working

    Posted 01/19/22 03:29 PM

    Hi Stefan,

    I know this effect too. In my case Windows log sources were affected in which MS-EVEN and not MS-EVEN6 was set as the event log poll protocol. After activating MSEVEN6 for the specific log sources, the payload was longer and also normalization worked better.

    Regards,

    Ralph



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: UDP max syslog payload length setting for managed host not working

    Posted 01/20/22 08:22 AM

    Thank you Ralph. Unfortunately it's already set to MSEVEN6. Due to the fact that there is no extra setting (at least on the front end) for managed hosts, I assumed that the value set on the system settings page will be used for all event collector services on all managed hosts, too. It seems that is wrong, maybe a bug?



    #QRadar
    #Support
    #SupportMigration