Hello everyone,
we want our Qradar (release 7.5.0.3) to ingest logs from a VmWare vCenter 8.0.
Does anybody know if there will be parsing issues? I know that vCenter DSM has just been updated to match the log format for vCenter 7, up to 2 months ago many event types were not correctly parsed and processed as "Stored".
In addition I would like to know if there is any way to filter logs that vCenter is sending and if gathering them via syslog or EMC VmWare protocol makes any difference from this point of view.
Thanks,
------------------------------
Davide Salardi
------------------------------