Hello,
we are collecting logs from an Apache webserver running on a Windows device, since syslog is not available, we are sending them to QRadar by WinCollect File Forwarder protocol.
Events show in event log window as unknown; we mapped most of them to QID in the DSM editor but they are still showing as unknown.
Is there anything we can do to solve? Has someone encountered the same issue?
B Regards
Davide
#QRadar#Support#SupportMigration