IBM QRadarJoin this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.
Many QRadar protocol sources that support collecting data streams that potentially contain data from multiple sources support the “Gateway Log Source” parameter. The following protocol sources are:
This allows you to split the logs back out into multiple log sources even though the data may have been aggregated into a single stream or is being collected by a single log source.
Log sources for the dynamic log source identifiers used are either automatically created (if the target DSM supports Traffic Analysis) or may be manually created with the specific DSM type and as Protocol type Syslog.
Copy