Hi Ciara,
I must warn you about the splunk forwader, because it hides some issues that just a few people know.
First, if you decide to use the forwader with the UDP protocol to forward to Qradar, you'll have a surprise. When set with UDP, the forwader adds an extra header before the log is sent. Therefore, if your log already had an header, then Qradar won't be able to parse the double header it receives. The splunk forwarder is not built like Qradar's forwarder. It doesn't check if the log already contains a header. It just adds one without any validation.
Secondly, if you use TCP protocol, then you've put splunk in trouble. The forwader sends the data to its indexers at the same time it forwards to Qradar. So in TCP, if Qradar stop responding, let's say it's restarting, then splunk will pause indexing and forwarding until Qradar is back online. That means that it's not sending the logs to its indexers during this time. Eventually, the splunk queue overflows, and data is lost. True story. As of today, January 20th, this is still a serious issue.
I know, this seems crazy, but it's how it works. We've open a ticket with splunk, and they're not doing anything about it. We've came out with a workaround, since splunk's forwader is too primitive.
I know you've developp this App, because a lot of Qradar clients asked for it, but it's quite risky. Unfortunately, my employer doesn't allow me to talk about our workaround solution. However, I will try to get approval. If I do, I'll be back to show you the best way to transfer logs from splunk to Qradar safely.
Regards,
------------------------------
Anthony Gayadeen
------------------------------
Original Message:
Sent: 09-21-2018 01:27 PM
From: Ciara Kennedy
Subject: New: IBM QRadar App For Splunk Data Forwarding v1.0.0
IBM QRadar App For Splunk Data Forwarding allows you to forward events from your Splunk Deployment to QRadar. Simply enter the IP of your Splunk instance, discover what data your Splunk instance is collecting, and then point and click to start forwarding your data to QRadar, enabling more security use cases. The app works with both the universal forwarder and heavy forwarder.
Download the new app from App Exchange.
------------------------------
Ciara Kennedy
------------------------------