IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Microsoft Exchange Audit and Admin Logs

    Posted Tue December 22, 2020 12:43 PM
    Hello all,
     
    I am having problems to pull audit and admin logs of exchange, do anyone know how to proceed with such integration.
     
    Best Regards,
    Ahmed Elsayed
    SIOC Analyst MEA
    IBM Egypt
     



  • 2.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Tue December 22, 2020 02:02 PM

    Ahmed

    very generic question. What about using wincollect? Pls outline how far you got with onboarding your windows logsource.

    br Karl 



    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------



  • 3.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Tue December 22, 2020 05:46 PM

    Hi Karl,

    Thank you for your reply.

    I am talking about Microsoft exchange server administrator audit logs, these logs are stored locally in a mailbox within the application itself and only accessible through cmdlets, there are softwares like (LOGbinder for Exchange) that pull the logs from the mailbox parse them and forward them to Qradar.

    the problem is that these softwares aren't free to use, I was thinking of extracting the logs and pull them from qradar, but not sure if this is the most suitable way to proceed with that.

    Thanks



    ------------------------------
    Ahmed Elsayed
    ------------------------------



  • 4.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Thu December 24, 2020 10:07 AM

    I think I noticed searching mentions of powershell scripts for the purpose of exporting Exchange audit logs/data. Maybe it could be viable to get a text/csv/xml this way and then you can pick it up and create your own parsing.



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 5.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Fri December 25, 2020 08:15 PM

    Yeah I've searched a lot for that and found that these logs need to be exported then get them into Qradar and parse them.

    Thanks Dusan.



    ------------------------------
    Ahmed Elsayed
    ------------------------------



  • 6.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Mon December 28, 2020 01:14 PM

    Hi Ahmed;

    First

    1- Build your own DSM named Exchange Audit

    2- Bind Wincollect as a protocol for this source

    3- Add XPATH Query; Path can e changeable according to your own path.

    <QueryList>
    <Query Id="0" Path="MSExchange Management">
    <Select Path="MSExchange Management">*</Select>
    </Query>
    </QueryList>



    ------------------------------
    Caglar Durmaz
    ------------------------------



  • 7.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Fri January 08, 2021 01:35 AM
    Hi Caglar,

    I've tried this but seems not working.

    Thanks

    ------------------------------
    Ahmed Elsayed
    ------------------------------



  • 8.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Sat December 26, 2020 10:37 AM

    Hi Ahmed,

    as a glance over ist seems to be a good way of integration to use logbinder. It is a supported way listed in DSM Guide as well. It sounds like a more comfortable onboarding those logrecords in case of parsing and normalisation to be used in QRadar.. regarding to cost-value ratio..

    Regards,

    Ralph



    ------------------------------
    Ralph Belfiore
    IT Security Senior Consulting
    pro4bizz GmbH
    Karlsruhe
    +49 721 90981720
    ------------------------------



  • 9.  RE: Microsoft Exchange Audit and Admin Logs

    Posted Sat December 26, 2020 12:33 PM

    Hi Ralph,

    Totally agree with you, I will propose that to the customer but I am sure to tell that it won't be considered.

    Without LOGbinder I think the mentioned approach is suitable for the integration.

    Thanks Ralph.



    ------------------------------
    Ahmed Elsayed
    ------------------------------