IBM Security QRadar

 View Only
Expand all | Collapse all

Integrating SCCM Logs into QRadar

  • 1.  Integrating SCCM Logs into QRadar

    Posted Fri August 23, 2019 04:36 PM
    Hi everyone,

    so we are currently looking at different antivirus option and one of them is going with Windows Defender which would be centralised in SCCM and so the question i have on this is as follows : Is there a way for us to collect such logs into QRadar ?

    Cheers,
    Alexandre Laquerre

    ------------------------------
    Alexandre Laquerre
    ------------------------------


  • 2.  RE: Integrating SCCM Logs into QRadar
    Best Answer

    Posted Mon August 26, 2019 03:26 AM
    I remember seeing in the DSM guide that Windows Defender is supported as log source (using REST API). So, if you would e.g. have the events collected in a separate section in SCCM's database, I guess it would probably mean preparing a custom specification using e.g. JDBC to read the events from the database (and mapping the events afterwards accordingly).

    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: Integrating SCCM Logs into QRadar

    Posted Mon August 26, 2019 09:30 AM
    Excellent,

    thank you very much for that :) 

    actually the collection can apparently be done via Microsoft Endpoint Protection through JDBC as you mentionned.

    Have a good Day.
    Alexandre LAquerre

    ------------------------------
    Alexandre Laquerre
    ------------------------------



  • 4.  RE: Integrating SCCM Logs into QRadar

    Posted Tue September 24, 2019 08:49 AM
    Edited by Mathieu Bouillaguet Tue September 24, 2019 10:23 AM
    Hi Alexandre,

    Could you confirm that you were able to collect Windows defender events by querying SCCM database and that the events are correctly parsed using the Microsoft Endpoint Protection DSM.

    If this is the case could you share some of your configuration.

    Thanks for your help.

    Regards

    ------------------------------
    Mathieu Bouillaguet
    ------------------------------



  • 5.  RE: Integrating SCCM Logs into QRadar

    Posted Tue September 24, 2019 04:10 PM
    Hi Mathieu,

    well we are still awaiting for the deployment phase so for now its a big no :)
    I will update this ticket  when we perform that test

    Regards,
    Alexandre Laquerre

    ------------------------------
    Alexandre Laquerre
    ------------------------------



  • 6.  RE: Integrating SCCM Logs into QRadar

    Posted Thu October 31, 2019 04:00 PM
    Hi Mathieu,

    so the collection is working which is with the Microsoft Endpoint Protection DSM - > MSDE - > Prequery Microsoft Endpoint Protection

    The issue is that all the logs that are collected are unknown and furthermore when reviewing the DSM (under DSM Editor ) i noticed under Event Mappings that all the mapping is done for ForeFront Endpoint Protection which is somewhat problematic since it should have mappings for SCEP as well.....
    Is there any documentation for Microsoft System Center Endpoint Protection (SCEP) .... 

    Regards,
    Alexandre Laquerre



    ------------------------------
    Alexandre Laquerre
    ------------------------------



  • 7.  RE: Integrating SCCM Logs into QRadar

    Posted Thu November 14, 2019 01:39 PM
    Hi,

    so the logs are now collecting however there seems to be a bit of a confusion on the ibm troubleshooting since it suggest for us to test out the query however when selecting the predefined query (Microsoft Endpoint Protection) it does not tell us what the query is which means we cannot really test it out.....
    Does anyone know what the predefined SQL query is ?

    Regards,
    Alexandre Laquerre

    ------------------------------
    Alexandre Laquerre
    ------------------------------



  • 8.  RE: Integrating SCCM Logs into QRadar

    Posted Tue October 27, 2020 04:18 AM
    Dear, 

    Will you share the log source creation for SCCM, i wanna cross check with my integration.

    Thanks.

    Saqib.

    ------------------------------
    saqib mehmood
    ------------------------------



  • 9.  RE: Integrating SCCM Logs into QRadar

    Posted Tue January 12, 2021 03:59 PM
    Hi.
    Were you able to resolve the issue with collecting SCEP logs in QRadar.

    ------------------------------
    Даниил Ивашин
    ------------------------------



  • 10.  RE: Integrating SCCM Logs into QRadar

    Posted Tue July 06, 2021 04:19 AM
    Hi,

    Eventually we manage to collect Windows Defender logs with the JDBC protocol.

    You just have to fill the mandatory parameters and choose "Microsoft Endpoint Protectio" for "Predefined Query".

    You will also need a valid account to query the database.

    After that, you can just test the log source.

    Regards

    ------------------------------
    Mathieu Bouillaguet
    ------------------------------