IBM Security QRadar

 View Only
  • 1.  F5 Integration With QRadar

    Posted 17 days ago

    Hi,

    I have configured a F5 log source in QRadar, the logs are successfully sending from the F5 device but not reaching to the QRadar.

    Verified in the unknown logs as well but not available.

    F5 Version: 17.x

    QRadar Version: 7.5.0 UP6

    Please assist me to resolve the issue.

    Thanks



    ------------------------------
    Arunkumar R
    ------------------------------


  • 2.  RE: F5 Integration With QRadar

    Posted 17 days ago

    Hi Arunkumar

    Are you seeing any errors?  Does a TCP dump show the events arriving at QRadar?

    Can you see any events with the same source IP?

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 3.  RE: F5 Integration With QRadar

    Posted 16 days ago

    Hi John,

    No errors, and still no events received.

    Yes, the TCP dump shows the events that arrive to QRadar.

    I could see the firewall events for this IP address.

    Thanks



    ------------------------------
    Arunkumar R
    ------------------------------



  • 4.  RE: F5 Integration With QRadar

    Posted 16 days ago

    Hi Arunkumar,

    I would suggest opening a case with support so we can review the configuration and the logs.

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 5.  RE: F5 Integration With QRadar

    IBM Champion
    Posted 16 days ago

    Couple of things, F5 events have huge payloads, so make sure to use TCP not UDP.  We also recommend the syslog payload limit be changed in setup to around 32K, with huge UDP support those can go larger as well. The F5 admins need to make sure they have the logging set in multiple place, just follow the IBM docs.  



    ------------------------------
    Frank Eargle
    ------------------------------