Hi Moustafa,
WinCollect agents send events to QRadar to port 514, unless they've been configured to use TLS Syslog, in which case it would be an alternate listen port.
Managed agents (those installed with a Configuration Server set) also talk to QRadar via an encrypted management channel, which QRadar listens for on port 8413. If you installed your agent as a manged agent, you need to ensure it has line-of-sight to both port 514 and port 8413 on the target QRadar host. If it's an unmanaged agent, meaning you configure the agent directly, you only need access to 514.
Your original post said you used the WinCollect File Forwarder protocol, which suggests you configured your log source on the QRadar side. This is for managed agents only, so you should check this file on your Windows system to verify that the ConfigurationServer property is set to a QRadar host which your agent can reach on 8413: C:\Program Files\IBM\WinCollect\config\install_config.txt
If the agent is properly connecting to QRadar for mangement purposes, it should have downloaded an AgentConfig.xml file to the same directory that contains your File Forwarder configuration. If the config file does not have this info, it means the agent is not getting config updates from QRadar, which likely means you have something misconfigured, but if you can't figure out what, you should contact support.
Cheers
Colin
------------------------------
COLIN HAY
IBM Security
------------------------------
Original Message:
Sent: Mon December 14, 2020 03:31 AM
From: Moustafa Salah
Subject: Wincollect File Forwarder Issue
Hello All,
Kindly i would like to ask if there is a required ports need to be open for these logsources, or there are any thing else need to be checked to confirm that everything is okay
Thank you.
------------------------------
Moustafa Salah
Original Message:
Sent: Tue December 01, 2020 03:40 AM
From: Moustafa Salah
Subject: Wincollect File Forwarder Issue
Hello all,
Wish you a Good Day,
Kindly I would like to ask about an Issue appeared to me as I use a Qradar v 7.3.3 Fixpack 3 and i want to get the Logs of the Oracle DB (raised on windows server) and the DB Retrieves it's logs in a file on this server so, I installed Wincollect in the Server and I used the Wincollect file forwarder Protocol to get the Logs from this file i followed the Steps that was found in the DSM Guide but the integration failed and there is no logs com to Qradar from this file is there another thing I should check about or is there another work around that make me get these logs from this files and kindly be informed that i was using Wincollect version 7.2.9.
Kindly any one help me with this issue ASAP.
Thanks.
------------------------------
Moustafa Salah
------------------------------