IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Parse Apache Logs

    Posted Wed July 21, 2021 10:16 AM

    Hello,

    we are collecting logs from an Apache webserver running on a Windows device, since syslog is not available, we are sending them to QRadar by WinCollect File Forwarder protocol.

    Events show in event log window as unknown; we mapped most of them to QID in the DSM editor but they are still showing as unknown.

    Is there anything we can do to solve? Has someone encountered the same issue?

    B Regards

    Davide



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: Parse Apache Logs

    Posted Wed July 21, 2021 01:08 PM

    Hi Davide,

    If you are collecting logs using WinCollect File Forwarder protocol, then you are better off writing your own custom DSM using DSM editor.

    Check this out:

    https://www.ibm.com/support/pages/creating-custom-dsm

    Have you already followed the above steps and still facing problem?



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: Parse Apache Logs

    Posted Fri July 23, 2021 02:32 PM

    Hi,

    thanks for your support.

    I have made a mistake in Log Source Extension Configuration..we had duplicated LSX so in some way it was crating a conflict when associating LSX to the log source.

    We have removed the duplicated LSX and wrote a new DSM in DSM editor, now everything is working as expected.

    B Regards

    Davide



    #QRadar
    #Support
    #SupportMigration


  • 4.  RE: Parse Apache Logs

    Posted Tue September 07, 2021 08:37 AM

    Hello,

    What are the required prerequisites to integrate the log file with QRadar using the WinCollect File Forwarder protocol as the server that has the log file already installed on it Managed WinCollect and receiving OS logs from it on QRadar?

    Regards,

    Omar



    #QRadar
    #Support
    #SupportMigration