IBM Security QRadar

 View Only
  • 1.  Same Log source added two times

    Posted Thu September 03, 2020 03:21 AM
    Same log source is added two times and giving different events, one discovery method was auto discovery and other one was manually discovered and these both same log source is giving different events.

    ------------------------------
    Ather Mobeen
    ------------------------------


  • 2.  RE: Same Log source added two times

    Posted Fri September 04, 2020 12:03 PM
    Normally a log source can not exist multiple times, given the identifier and log source type are also the same. There can be multiple log sources for one identifier, given they are all different log source types, for example one Juniper FW log source and a Linux log source with the same hostname as identifier.

    For your case, can you check if the identifier is exactly the same. If yes, is also the log source type the same?


  • 3.  RE: Same Log source added two times

    Posted Sun September 06, 2020 05:56 AM
    can u provide any source to get more info about this issue.

    ------------------------------
    Preeti Batra
    ------------------------------



  • 4.  RE: Same Log source added two times

    Posted Thu September 10, 2020 02:37 AM
    The issue is resolved from changing the log parsing order of the devices that are added two times.

    ------------------------------
    Ather Mobeen
    ------------------------------