IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  wincollect 10 and forwarded events

    Posted Sun February 04, 2024 10:24 AM

    i have A case , i have A server it has wincollect 10 and there arse some logs are forwarded to it , so i crete a new source on wincollect to the new channel with xpath , and it comming but under the same log source , so how i can make it comming under new log source



    ------------------------------
    osama ahmed
    ------------------------------


  • 2.  RE: wincollect 10 and forwarded events

    Posted Wed February 28, 2024 08:59 AM

    Hi Osama,

    In WinCollect 10 you can set an Identifier Override:

    1. Open the WinCollect 10 console in Windows.
    2. From the cogwheel icon in the top right corner, enable Advanced UI.
    3. From the ☰ menu, go to Local Sources.
    4. Open the local collection group where you can see the Channels.
    5. Open the Sources> XPath config.
    6. Now you can see the Identifier Override field. Enter a value to be used as a Log Source Identifier, which you will use in a log source config on the QRadar side.
    7. Save and Apply the changes.

    If there's enough events from this Source, the log source should now get auto-detected (auto-created).

    Hope this is helpful!

    -C-



    ------------------------------
    Carl Mohn
    IBM
    Dublin
    ------------------------------



  • 3.  RE: wincollect 10 and forwarded events

    Posted Mon March 04, 2024 04:13 AM

    Dear Carl Mohn,

    thank for your reply , i tested it and it work 



    ------------------------------
    osama ahmed
    ------------------------------



  • 4.  RE: wincollect 10 and forwarded events

    Posted Mon March 04, 2024 04:24 AM

    Osama, glad to hear! :) Good luck!

    BR,

    -C-



    ------------------------------
    Carl Mohn
    IBM
    Dublin
    ------------------------------