IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Syslog TLS 6514 port issue

    Posted Mon May 05, 2025 04:12 PM

    Hi guys,

    I want to transfer the logs of a resource on the cloud to the qradar I use inside, for this I defined a vip towards the public ip and I saw that this step passed through the FW, but these logs do not come to Qradar. When I run netstat -tuln | grep 6514, the output comes blank. When I create a log source on Qradar and test it, I get the following error. what should I do?
     
    Testing SSL connection to [127.0.0.0.1:6514]
    Initiating SSL handshake to [127.0.0.1:6514] with a timeout of 10000 ms
    Error: Unable to connect to host [127.0.0.1] on port [6514]: Connection refused (Connection refused)
     
    Thanks in advance


    ------------------------------
    Adem Güler
    ------------------------------


  • 2.  RE: Syslog TLS 6514 port issue

    Posted Mon May 05, 2025 04:15 PM

    Did you deploy and re-try the test? It's not obvious but the protocols that listen have to be deployed the first time they are setup.



    ------------------------------
    Rory Bray
    Security and Compliance Architect, Threat Management
    IBM
    ------------------------------



  • 3.  RE: Syslog TLS 6514 port issue

    Posted Mon May 05, 2025 04:18 PM

    I didn't create a log source because the test failed, what I was expecting here was that traffic would be generated and see the source itself.



    ------------------------------
    Adem Güler
    ------------------------------



  • 4.  RE: Syslog TLS 6514 port issue

    Posted Mon May 05, 2025 04:20 PM

    OK, that's probably the issue. Go ahead and create the log source and deploy. That will start the server on port 6514 (it isn't running by default).



    ------------------------------
    Rory Bray
    Security and Compliance Architect, Threat Management
    IBM
    ------------------------------



  • 5.  RE: Syslog TLS 6514 port issue

    Posted Mon May 05, 2025 04:48 PM

    Yes, it worked this way, thanks for your attention.



    ------------------------------
    Adem Güler
    ------------------------------