Hello,
Created new LogSource - "QRadar Collector Monitor"
It receiving logs from Python script in console, which checking SSH connectivity between console and Event Processors.
Log example:
<14>soc-nvd-metrics INFO:check_ssh_connectivity.py:74 - 2024-10-11 11:50:01,759 - Host VTM (SOCS0000033) | (192.168.5.72) SSH Domain:(VTM) Connection Status: Inactive
Created new Log Source Type - "QRadar Collector Monitor - TETv2" and parsed and mapped all properties.
Issue - Qradar using Default Event-Mapping, and store incoming events. Why it not using created Event-Mapping ?
For example - After added new property - 'Source IP', which should be 127.0.0.1, in Log Activity Source IP still is 255.255.255.255
So basically Log Source using appropriate Log Source Type, but not showing any of in DSM created properties.
------------------------------
Vladislavs Lipskis
------------------------------