It is hard to tell without viewing the payload. Generally, SIM Generic would appear when the ingested content is not in a form that would be recognized automatically by QRadar to create the appropriate log source. If you created a log source but logs still go to SIM Generic, then you probably used a wrong log source identifier. Compare the payload from Ububtu to what comes in from other Linux log sources that behave correctly. I recall having an Ubuntu-based system with auditd installed and logging was OK at the time.
------------------------------
Dusan VIDOVIC
------------------------------
Original Message:
Sent: Thu August 10, 2023 05:10 AM
From: Sugandhini PS
Subject: Unable to parse logs from Ubuntu machine ,but can parse other Linux logs
Unable to parse logs from Ubuntu machine ,but can parse other Linux logs ,could someone please help me with what DSM to be used or the process to be followed
------------------------------
Sugandhini PS
------------------------------