IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Wincollect forwarded logs for one server/IP has two different hostnames

    Posted Wed September 04, 2024 09:58 AM

    Hi,

    we have Windows security event logs from multiple servers  forwarded through the domain policy to Wincollect collector server and then to Qradar.

    I did notice that one server is sending logs with two different Logsource identifiers. One is in fqdn format FS-CI-PP-01.eagle.birds.com and the second is just FS-CI-PP-01.

    From the FS-CI-PP-01.eagle.birds.com we are getting logs types Applications, Security, System which is how it should be.

    From FS-CI-PP-01 we are getting just two event names from Application type logs. These events names are possibly related to RDP sessions.

    This means that we have two Logsources for one server/IP in Qradar which isn't how I like it :)

    Does anyone know what could be the reason of this behavior?

    Regards

    T



    ------------------------------
    tysa
    ------------------------------


  • 2.  RE: Wincollect forwarded logs for one server/IP has two different hostnames

    Posted Thu September 05, 2024 03:03 AM

    Hello Tysa,

    Did you try changing the identifier to FS-CI-PP-01. So that both events will get detected by single log source.



    ------------------------------
    Vishal Tangadkar
    IBM INDIA PVT LTD
    ------------------------------



  • 3.  RE: Wincollect forwarded logs for one server/IP has two different hostnames

    Posted Thu September 05, 2024 04:06 AM

    Hello Vishal,

    Do you mean to change it in the Qradar Log Source Management>Logsource Name>Protocol>Log Source Identifier?

    Because if yes, I don't think that would help. I think that way the logs with identifier FS-CI-PP-01.eagle.birds.com would finish in the SIM Generic Log DSM 7.

    Regards

    Tysa



    ------------------------------
    tysa
    ------------------------------