IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Jenkins Logs to Qradar

    Posted 21 days ago

    Hi team,

    We want to send Jenkins logs into Qradar. Has anyone experienced this issue before?

    Thanks in advance



    ------------------------------
    Adem Güler
    ------------------------------


  • 2.  RE: Jenkins Logs to Qradar

    Posted 18 days ago

    There is this syslog plugin https://plugins.jenkins.io/syslog-logger/ It is old but still seems to work. QRadar probably will not detect the logsource and events out of the box so you should configure the dsm and event properties yourself



    ------------------------------
    Erwin
    ------------------------------



  • 3.  RE: Jenkins Logs to Qradar

    Posted 17 days ago

    Hi,

    In fact, there is a nested structure here and the .log files in these directories are desired to be retrieved. I guess syslog does not exactly correspond to this.



    ------------------------------
    Adem Güler
    ------------------------------



  • 4.  RE: Jenkins Logs to Qradar

    Posted 12 days ago

    Hi Adem, Sorry for the slow respone!  If you are able to connect to the Jenkins server with ssh/scp you could use the universal DSM log source type and the log file protocol to retrieve the files



    ------------------------------
    Erwin
    ------------------------------



  • 5.  RE: Jenkins Logs to Qradar

    Posted 12 days ago

    Hi Erwin,

    Because of there are too many nested files, the log file protocol is timeout.



    ------------------------------
    Adem Güler
    ------------------------------