IBM Security QRadar

 View Only
  • 1.  Database log source integration IBM Qradar issues

    Posted 23 days ago

    Hi Team,
    Database logs are stored in binary format on server. 
    is it possible to integrate IBM Qradar with these binary log sources ? if yes, kindly help me with process.
    Below are the Server OS and  DB details.
    Windows(Maria/Postgre)
    Linux (Maria, postgre and MYSQL)



    ------------------------------
    Anurag Patel
    ------------------------------


  • 2.  RE: Database log source integration IBM Qradar issues

    Posted 17 days ago

    Hello Anurag,

    There is no tool which can read the binary format logs. You need to find someway to populate it in event / log format so that later those can be send 
    Whether any of these logs are part of database it self or whether same logs can be populated in any table ? If yes. then you can use JDBC protocol.
    https://www.ibm.com/docs/sr/dsm?topic=labs-jdbc-protocol-configuration-options




    ------------------------------
    Vishal Tangadkar
    IBM Software Support
    IBM INDIA PVT LTD
    ------------------------------



  • 3.  RE: Database log source integration IBM Qradar issues

    Posted 17 days ago

    Thank you for your input.

    These logs are database itself.

    Can we do anything from DB server side... I mean can we convert these binary logs to readable/plaintext format?



    ------------------------------
    Anurag Patel
    ------------------------------



  • 4.  RE: Database log source integration IBM Qradar issues

    Posted 12 days ago

    Hello Anurag,

    Nope nothing can be done from QRadar side as well which will do the conversion. 



    ------------------------------
    Vishal Tangadkar
    IBM Software Support
    IBM INDIA PVT LTD
    ------------------------------



  • 5.  RE: Database log source integration IBM Qradar issues

    Posted 11 days ago

    Thank you so much .



    ------------------------------
    Anurag Patel
    ------------------------------