IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Getting Azure NSG flow logs

    Posted Thu January 12, 2023 08:03 AM
    Hi! Needed help with adding Azure NSG flows logs to QRadar (Introduction to flow logging for NSGs - Azure Network Watcher | Microsoft Learn). As i read in documentations Azure NSG flow logs can not be flowed to event hub. This is a problem how to flow logs can be pulled to QRadar. As variants of integrations i found https://azsiempublicdrops.blob.core.windows.net/drops/Azure%20SIEM%20Integrator%20User%20Guide.pdf or Connect to Azure Event Hubs - Azure Logic Apps but this varianta not seems as a functional. May be somebody already has such integration?

    ------------------------------
    Serhii Barabash
    ------------------------------


  • 2.  RE: Getting Azure NSG flow logs

    Posted Mon February 27, 2023 01:34 PM

    Hi Serhii, support for Azure NSG flow logs (and the ability to covert them to flows in QRadar) is being added and should be available in a few months.



    ------------------------------
    Tom Obremski
    ------------------------------



  • 3.  RE: Getting Azure NSG flow logs

    Posted Mon September 18, 2023 09:24 AM

    Hi Tom.

    Is there any word on a timeframe for that Azure NSG flow log support?

    DH



    ------------------------------
    Dow Hartley
    ------------------------------



  • 4.  RE: Getting Azure NSG flow logs

    Posted Tue September 26, 2023 04:51 PM

    Hi Tom,

    Is there any ETA for Azure NSG flow log support?



    ------------------------------
    Aman Raj
    ------------------------------



  • 5.  RE: Getting Azure NSG flow logs

    Posted Wed October 09, 2024 07:04 AM

    Hello Tom, any update on this? Did I properly understand, qRadar would be able to directly read the NSG Logs from a Storage Account, like Splunk is able to? Thank you ;)



    ------------------------------
    Alex Schmitt
    ------------------------------



  • 6.  RE: Getting Azure NSG flow logs

    Posted Wed October 09, 2024 07:04 AM

    Hello Tom,

    any update on this please?

    Goal is that qRadar reads the logs directly from the Storage Accounts right?

    Thanks.



    ------------------------------
    Alex Schmitt
    ------------------------------