IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Windows log forward to IBM Qradar using Wincollect

    Posted Mon March 03, 2025 11:09 AM
      |   view attached

    Hello all,

    hope you all are doing well,

    I have multiple PCs and laptops  from which I intend to send logs to QRadar using the WinCollect Agent in standalone mode. However, after configuring the agent to send logs to QRadar, restarting the WinCollect service, and applying a source IP filter in the Log Activity tab to monitor the logs, I find that the log source is not being added to QRadar.

    and 2nd thing,if i added log source by manually then event name look like this  in attached picture

    Could you provide guidance on troubleshooting this issue?

    Your swift response will highly appreciated,

    Regards,

    Osama Ahmed



    ------------------------------
    Osama Ahmed
    ------------------------------


  • 2.  RE: Windows log forward to IBM Qradar using Wincollect

    Posted Thu March 06, 2025 10:19 AM

    I am having the same problem



    ------------------------------
    Advid Tran
    ------------------------------



  • 3.  RE: Windows log forward to IBM Qradar using Wincollect

    Posted Fri March 07, 2025 02:24 AM

    Osama, I could not see the picture. Did you confirm that the events arrive to QRadar instance (i.e. do you see them under SIM Generic log source)? If so, can you also post the sample log (anonymise the IPs and/or username, of course).



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 4.  RE: Windows log forward to IBM Qradar using Wincollect

    Posted Sat March 08, 2025 01:51 PM
    Edited by Abdul Quadeer Sat March 08, 2025 01:54 PM

    Hi,

    From the snap it's clear that event name is same as LS name. If possible, could you please share config file content of wincollect agent? Don't forget to hide sensitive data in the file.


    ------------------------------
    Abdul Quadeer
    ------------------------------



  • 5.  RE: Windows log forward to IBM Qradar using Wincollect

    Posted Mon March 10, 2025 02:14 AM
      |   view attached

    Hello,

    Thanks for your kind response, the issue has been resolved by manual adding log source snap are attached please review again thanks



    ------------------------------
    Osama Ahmed
    ------------------------------



  • 6.  RE: Windows log forward to IBM Qradar using Wincollect

    Posted Mon March 10, 2025 02:16 AM
      |   view attached

    Hello Abdul,

    the issue has been resolved by manual adding log source snap are attached.



    ------------------------------
    Osama Ahmed
    ------------------------------



  • 7.  RE: Windows log forward to IBM Qradar using Wincollect
    Best Answer

    Posted Mon March 10, 2025 04:23 AM
    Edited by Sejid Canoski Mon March 10, 2025 06:52 AM

    Hello Osama,

    first of all I red that the issue has been solved. Glad to hear that.

    However I like to add some guidance to troubleshoot this issue if it happens again in the future. 

    From the attached screenshot I can see that the Low-Level-Category is "Stored". 
    In QRadar a Stored Event means that QRadar cannot understand or cannot properly parse the incoming event. The event is still written to disk and displayed.
    Please try to also capture the High-Level-Category in the future. 
    The reason for that is if the High-Level-Category is "Unknown" that would indicate that the event is collected and parsed, but cannot be mapped or categorized to a specific log source. The event will be associated with the SIM Generic log source.

    In your case you should double click a stored event and compare the raw payload with the normalized field (the parsed events, e.g Source IP, Destination IP, ...). If you see that content is not properly extracted, you know that the event is not properly processed.
    Double check if the auto-detected or manually added log source is correctly configured.

    If the Log Source is correctly configured you can select the stored events in the Log Activity and under Actions open the DSM Editor. 
    In the DSM Editor you can see how QRadar is parsing the event. Here you can either add properties and parse them properly or override system behavior for not properly parsed values. Additionally you can adjust the event mapping.

    Following links to the official documentation:

    1. High-level event categories
    2. Low-level event categorie: Stored
    3. Troubleshooting DSMs
    4. DSM Editor Overview

    I hope this helps for future events. 

    Stay cyber resilient,
    Sejid



    ------------------------------
    Sejid Canoski
    Technical Presales Consultant/Architect
    TD SYNNEX Germany GmbH & Co. OHG
    Munich
    ------------------------------



  • 8.  RE: Windows log forward to IBM Qradar using Wincollect

    Posted Mon March 10, 2025 05:50 AM

    Hi Sejid,

    Noted with thanks :)



    ------------------------------
    Osama Ahmed
    ------------------------------