Hello,
I do not see any current support for this at present:
As per the DSM guides:
https://www.ibm.com/docs/en/dsm?topic=configuration-qradar-supported-dsms
When a device is not officially supported, you have the following options:
- Open a request for enhancement (Now IBM Ideas) to have your device become officially supported.
Go to the QRadar SIEM RFE page (https://ibm.biz/BdRPx5).
You can follow the technote as well.
https://www.ibm.com/support/pages/qradar-requesting-new-features-ibm-ideas
rasing the idea under 'QRadar Integrations - Device Support Modules (DSMs), Scanners, Rules, and Reports'
Regards,
------------------------------
Comghall Morgan
QRadar Support Architect
IBM
------------------------------
Original Message:
Sent: Fri June 07, 2024 07:30 AM
From: Edgar Faria
Subject: CrowdStrike Falcon FileVantage logs to QRadar
Hi all,
Does anyone know if it is possible to send CrowdStrike Falcon FileVantage logs to QRadar?
Best Regards.
------------------------------
Edgar Faria
------------------------------