IBM QRadar

 View Only
  • 1.  wincollect 10 and forwarded events

    Posted Sun February 04, 2024 10:24 AM

    i have A case , i have A server it has wincollect 10 and there arse some logs are forwarded to it , so i crete a new source on wincollect to the new channel with xpath , and it comming but under the same log source , so how i can make it comming under new log source



    ------------------------------
    osama ahmed
    ------------------------------


  • 2.  RE: wincollect 10 and forwarded events

    Posted Wed February 28, 2024 08:59 AM

    Hi Osama,

    In WinCollect 10 you can set an Identifier Override:

    1. Open the WinCollect 10 console in Windows.
    2. From the cogwheel icon in the top right corner, enable Advanced UI.
    3. From the ☰ menu, go to Local Sources.
    4. Open the local collection group where you can see the Channels.
    5. Open the Sources> XPath config.
    6. Now you can see the Identifier Override field. Enter a value to be used as a Log Source Identifier, which you will use in a log source config on the QRadar side.
    7. Save and Apply the changes.

    If there's enough events from this Source, the log source should now get auto-detected (auto-created).

    Hope this is helpful!

    -C-



    ------------------------------
    Carl Mohn
    IBM
    Dublin
    ------------------------------



  • 3.  RE: wincollect 10 and forwarded events

    Posted Mon March 04, 2024 04:13 AM

    Dear Carl Mohn,

    thank for your reply , i tested it and it work 



    ------------------------------
    osama ahmed
    ------------------------------



  • 4.  RE: wincollect 10 and forwarded events

    Posted Mon March 04, 2024 04:24 AM

    Osama, glad to hear! :) Good luck!

    BR,

    -C-



    ------------------------------
    Carl Mohn
    IBM
    Dublin
    ------------------------------